Quay: cross-site request forgery (csrf) on config-editor page
Vulnerability Description
A flaw was found in Quay. Cross-site request forgery (CSRF) attacks force a user to perform unwanted actions in an application. During the pentest, it was detected that the config-editor page is vulnerable to CSRF. The config-editor page is used to configure the Quay instance. By coercing the victim’s browser into sending an attacker-controlled request from another domain, it is possible to reconfigure the Quay instance (including adding users with admin privileges).
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2023-4959
Credits & Attribution
The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:
- This issue was discovered by Oleg Sushchenko (Red Hat).
References
More from Red Hat
View All →Affected Vendor
Red Hat
View all reports →