ZeroHour

CVE-2019-3865

CVSS 3.1
6.1 medium
EPSS
<1%p52
Published
()
Modified
Description

A vulnerability was found in quay-2, where a stored XSS vulnerability has been found in the super user function of quay. Attackers are able to use the name field of service key to inject scripts and make it run when admin users try to change the name.

Vendors
redhat
Products
quay
Weakness
CWE-79
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

In the news

No ingested article mentions this CVE yet.