← Vulnerability feed

Vulnerability record · CVE-2019-3864 · published 21 January 2020

CVE-2019-3864: Redhat quay cross-site request forgery vulnerability

Redhat · Quay

A vulnerability was discovered in all quay-2 versions before quay-3.0.0, in the Quay web GUI where POST requests include a specific parameter which is used as a CSRF token. The token is not refreshed for every request or when a user logged out and in again. An attacker could use a leaked token to gain access to the system using the user's account.

8.8 CVSS 3.1 High EPSS 0.44% · top 64.2% CWE-352 · Cross-site request forgery
8.8CVSS 3.1 base score, v2 6.8
0.44%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
2References
17 Jun 2026Last modified by NVD

Description

A vulnerability was discovered in all quay-2 versions before quay-3.0.0, in the Quay web GUI where POST requests include a specific parameter which is used as a CSRF token. The token is not refreshed for every request or when a user logged out and in again. An attacker could use a leaked token to gain access to the system using the user's account.

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2019-3864 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

7.5CVE-2023-44487HTTP/2 Rapid Reset stream cancellation denial of serviceThe HTTP/2 protocol permits a client to cancel many streams quickly, and the server's handling of those resets consumes disproportionate resources. T…KEVEPSS 100%analysed9.8CVE-2021-3762Redhat clair path traversal vulnerabilityA directory traversal vulnerability was found in the ClairCore engine of Clair. An attacker can exploit this by supplying a crafted container image w…EPSS 4.8%9.0CVE-2020-27832Redhat quay cross-site scripting vulnerabilityA flaw was found in Red Hat Quay, where it has a persistent Cross-site Scripting (XSS) vulnerability when displaying a repository's notification. Thi…EPSS 0.91%8.8CVE-2026-32590Redhat mirror registry for red hat openshift deserialization of untrusted data vulnerabilityA flaw was found in Red Hat Quay's handling of resumable container image layer uploads. The upload process stores intermediate data in the database u…EPSS 0.79%8.8CVE-2022-1227Podman project podman improper privilege management vulnerabilityA privilege escalation flaw was found in Podman. This flaw allows an attacker to publish a malicious image to a public registry. Once this image is d…EPSS 4.2%8.2CVE-2026-74243Redhat openshift update service missing authentication for critical function vulnerabilityA flaw was found in Red Hat Quay. When the SECURITY_SCANNER_V4_PSK (pre-shared key) is not set, a remote unauthenticated attacker can send POST reque…EPSS 0.46%8.1CVE-2026-6848Redhat quay insufficient session expiration vulnerabilityA flaw was found in Red Hat Quay. When Red Hat Quay requests password re-verification for sensitive operations, such as token generation or robot acc…EPSS 0.38%7.7CVE-2026-44495Axios code injection vulnerabilityAxios is a promise based HTTP client for the browser and Node.js. From 0.19.0 to before 0.31.1 and 1.15.2, Axios contains prototype-pollution gadgets…EPSS 1.0%

Source: NIST National Vulnerability Database (record CVE-2019-3864), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.