Description
A flaw was found in Quay. Clickjacking is when an attacker uses multiple transparent or opaque layers to trick a user into clicking on a button or link on another page when they intend to click on the top-level page. During the pentest, it has been detected that the config-editor page is vulnerable to clickjacking. This flaw allows an attacker to trick an administrator user into clicking on buttons on the config-editor panel, possibly reconfiguring some parts of the Quay instance.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
Vendor Workaround
It is recommended to configure the webserver to perform the inclusion of the X-Frame-Options: Deny header.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2023-54792 | A flaw was found in Quay. Clickjacking is when an attacker uses multiple transparent or opaque layers to trick a user into clicking on a button or link on another page when they intend to click on the top-level page. During the pentest, it has been detected that the config-editor page is vulnerable to clickjacking. This flaw allows an attacker to trick an administrator user into clicking on buttons on the config-editor panel, possibly reconfiguring some parts of the Quay instance. |
References
History
No history.
Status: PUBLISHED
Assigner: redhat
Published:
Updated: 2025-11-07T00:46:07.885Z
Reserved: 2023-09-14T04:52:43.812Z
Link: CVE-2023-4956
No data.
Status : Modified
Published: 2023-11-07T20:15:08.970
Modified: 2024-11-21T08:36:20.217
Link: CVE-2023-4956
OpenCVE Enrichment
No data.
Weaknesses
EUVD