Severity
6.1MEDIUM
EPSS
0.3%
top 42.88%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedJun 22
Latest updateMay 24

Description

A vulnerability was found in quay-2, where a stored XSS vulnerability has been found in the super user function of quay. Attackers are able to use the name field of service key to inject scripts and make it run when admin users try to change the name.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:NExploitability: 2.8 | Impact: 2.7

Affected Packages2 packages

NVDredhat/quay2.0.0
CVEListV5[unknown]/quayquay 2

🔴Vulnerability Details

2
GHSA
GHSA-pgwc-cqjm-w595: A vulnerability was found in quay-2, where a stored XSS vulnerability has been found in the super user function of quay2022-05-24
CVEList
CVE-2019-3865: A vulnerability was found in quay-2, where a stored XSS vulnerability has been found in the super user function of quay2020-06-22

📋Vendor Advisories

48
Red Hat
quay: Stored XSS in super user function2019-11-03
Red Hat
chromium-browser: Use-after-free in IndexedDB2019-10-10
Red Hat
chromium-browser: Use-after-free in audio2019-10-10
Red Hat
chromium-browser: Cross-origin size leak2019-10-10
Red Hat
chromium-browser: Use-after-free in WebRTC2019-10-10

💬Community

1
Bugzilla
CVE-2019-3865 quay: Stored XSS in super user function2019-11-04