Redhat

Openshift Update Service

9 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.13%
  • Veröffentlicht 14.08.2026 22:43:15
  • Zuletzt bearbeitet 20.08.2026 19:59:12

A flaw was found in Red Hat Quay. A user with FEATURE_BUILD_SUPPORT enabled and repository write access can exploit a Server-Side Request Forgery (SSRF) vulnerability within the build API. This allows the user to provide a malicious URL, causing the ...

  • EPSS 0.31%
  • Veröffentlicht 14.08.2026 22:43:10
  • Zuletzt bearbeitet 20.08.2026 20:05:07

A flaw was found in Red Hat Quay's exported logs feature. An unauthenticated attacker with a valid file ID could download exported action logs without proper authorization. While file IDs are complex, they can be intercepted from plaintext email or w...

  • EPSS 0.26%
  • Veröffentlicht 14.08.2026 22:43:06
  • Zuletzt bearbeitet 20.08.2026 19:49:07

A flaw was found in Red Hat Quay. When the SECURITY_SCANNER_V4_PSK (pre-shared key) is not set, a remote unauthenticated attacker can send POST requests to the security scanner notification endpoint. This allows the attacker to flood the notification...

  • EPSS 0.14%
  • Veröffentlicht 14.08.2026 22:43:06
  • Zuletzt bearbeitet 20.08.2026 20:01:38

A flaw was found in Red Hat Quay's Stripe billing webhook handler. This vulnerability allows an unauthenticated attacker to forge billing events by sending crafted JSON requests to the `/webhooks/stripe` endpoint without validating the Stripe-Signatu...

  • EPSS 0.26%
  • Veröffentlicht 14.08.2026 22:43:04
  • Zuletzt bearbeitet 20.08.2026 19:00:11

A flaw was found in Red Hat Quay. An administrator of any repository, by knowing or guessing a target notification's Universally Unique Identifier (UUID), can read the notification configuration, including sensitive details like webhook URLs, Slack t...

  • EPSS 0.18%
  • Veröffentlicht 14.08.2026 22:43:02
  • Zuletzt bearbeitet 20.08.2026 19:13:47

A flaw was found in Red Hat Quay's external Lightweight Directory Access Protocol (LDAP) authentication handling. When an LDAP referral is returned during authentication, the system does not properly escape the username input. This allows an attacker...

  • EPSS 0.19%
  • Veröffentlicht 14.08.2026 22:43:01
  • Zuletzt bearbeitet 20.08.2026 19:45:42

A flaw was found in Red Hat Quay's JWT (JSON Web Token) validation for federated robot accounts and single sign-on (SSO) authentication. Multiple issues related to audience verification and the enforcement of `azp` and `sub` claims were identified. T...

  • EPSS 0.21%
  • Veröffentlicht 24.07.2026 06:36:18
  • Zuletzt bearbeitet 24.07.2026 20:49:03

A flaw was found in Red Hat Quay's notification webhook feature. The Slack and generic webhook notification handlers accept user-supplied URLs without SSRF validation, allowing a repository administrator to make the Quay worker issue POST requests to...

  • EPSS 0.15%
  • Veröffentlicht 08.04.2026 13:55:06
  • Zuletzt bearbeitet 24.07.2026 20:10:00

A container privilege escalation flaw was found in certain OpenShift Update Service (OSUS) images. This issue stems from the /etc/passwd file being created with group-writable permissions during build time. In certain conditions, an attacker who can ...