Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2023-4959

A flaw was found in Quay. Cross-site request forgery (CSRF) attacks force a user to perform unwanted actions in an application. During the pentest, it was detected that the config-editor page is vulnerable to CSRF. The config-editor page is used to configure the Quay instance. By coercing the victim’s browser into sending an attacker-controlled request from another domain, it is possible to reconfigure the Quay instance (including adding users with admin privileges).
Exploit prediction scoring system (EPSS) score
EPSS Score 0.001
EPSS Ranking 29.8%
CVSS Severity
CVSS v3 Score 6.5
Products affected by CVE-2023-4959
  • Redhat » Quay » Version: 3.0.0
    cpe:2.3:a:redhat:quay:3.0.0


Contact Us

Shodan ® - All rights reserved