CVE-2019-3867
published 2021-03-18CVE-2019-3867: A vulnerability was found in the Quay web application. Sessions in the Quay web application never expire. An attacker, able to gain access to a session, could…
PriorityP413medium4.1CVSS 3.1
AVPACLPRNUIRSUCLILAL
EPSS
0.29%
21.3th percentile
A vulnerability was found in the Quay web application. Sessions in the Quay web application never expire. An attacker, able to gain access to a session, could use it to control or delete a user's container repository. Red Hat Quay 2 and 3 are vulnerable to this issue.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| redhat | quay | — | — |
| redhat | quay | — | — |
| redhat | quay | — | — |
CVSS provenance
nvdv3.14.1MEDIUMCVSS:3.1/AV:P/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L
nvdv2.04.4MEDIUMAV:L/AC:M/Au:N/C:P/I:P/A:P
vendor_redhat4.1MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-pf92-7x8p-6x5m: A vulnerability was found in the Quay web application
ghsa_unreviewed·2022-05-24
CVE-2019-3867 [MEDIUM] CWE-613 GHSA-pf92-7x8p-6x5m: A vulnerability was found in the Quay web application
A vulnerability was found in the Quay web application. Sessions in the Quay web application never expire. An attacker, able to gain access to a session, could use it to control or delete a user's container repository. Red Hat Quay 2 and 3 are vulnerable to this issue.
Red Hat
quay: insufficient session expiration
vendor_redhat·2021-03-17·CVSS 4.1
CVE-2019-3867 [MEDIUM] CWE-613 quay: insufficient session expiration
quay: insufficient session expiration
A vulnerability was found in the Quay web application. Sessions in the Quay web application never expire. An attacker, able to gain access to a session, could use it to control or delete a user's container repository. Red Hat Quay 2 and 3 are vulnerable to this issue.
A vulnerability was found in the Quay web application. Sessions in the Quay web application never expire. An attacker, able to gain access to a session, could use it to control or delete a user's container repository.
Mitigation: Toggle 'FEATURE_PERMANENT_SESSIONS' to 'False' in quay.conf.
Package: quay (Red Hat Quay 2) - Will not fix
Package: quay (Red Hat Quay 3) - Will not fix
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2019-3867 quay: insufficient session expiration
bugzilla·2019-11-14·CVSS 4.1
CVE-2019-3867 [MEDIUM] CVE-2019-3867 quay: insufficient session expiration
CVE-2019-3867 quay: insufficient session expiration
Sessions in the Quay web application never expire. An attacker able to gain access to a session could use it to control, or delete a users container repository.
Discussion:
Acknowledgments:
Name: Jeremy Choi (Red Hat)
---
Mitigation:
Toggle 'FEATURE_PERMANENT_SESSIONS' to 'False' in quay.conf.
---
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s):
https://access.redhat.com/security/cve/cve-2019-3867
Bugzilla
CVE-2018-16838 sssd: improper implementation of GPOs due to too restrictive permissions
bugzilla·2018-10-18·CVSS 5.4
CVE-2018-16838 [MEDIUM] CVE-2018-16838 sssd: improper implementation of GPOs due to too restrictive permissions
CVE-2018-16838 sssd: improper implementation of GPOs due to too restrictive permissions
A flaw was found in sssd Group Policy Objects implementation. When the GPO is not readable by SSSD due to a too strict permission settings on the server side, SSSD will allow all authenticated users to login instead of denying access.
Discussion:
Upstream fix : https://pagure.io/SSSD/sssd/c/ad058011b6b75b15c674be46a3ae9b3cc5228175
---
Reference:
https://pagure.io/SSSD/sssd/issue/3867
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 7
Via RHSA-2019:2177 https://access.redhat.com/errata/RHSA-2019:2177
---
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s):
https://access.redhat.com/security/cve/cve-2018-1683
2021-03-18
Published