CVE-2019-3864: Red Hat Quay
High severity, CVSS 8.8. EPSS: 0.4% chance of exploitation in the next 30 days.
A vulnerability was discovered in all quay-2 versions before quay-3.0.0, in the Quay web GUI where POST requests include a specific parameter which is used as a CSRF token. The token is not refreshed for every request or when a user logged out and in again. An attacker could use a leaked token to gain access to the system using the user's account.
Affected products
- Red Hat Quay: before 3.0.0 (fixed in 3.0.0)
Published 2020-01-21. Last modified 2026-06-17.