Redhat

Quay

52 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.2%
  • Veröffentlicht 05.10.2026 21:16:34
  • Zuletzt bearbeitet 06.10.2026 15:09:20

A flaw was found in Quay. When handling build trigger requests, the application incorrectly exposes trigger configuration details containing repository write tokens to global read-only administrative users. An authenticated user with read-only privil...

  • EPSS 0.29%
  • Veröffentlicht 05.10.2026 17:02:51
  • Zuletzt bearbeitet 06.10.2026 15:09:20

A flaw was found in Quay. A remote attacker could trick a user into logging in through a crafted link, resulting in cross-site scripting (XSS). Because the application does not validate the redirect destination before navigating, this flaw allows the...

  • EPSS 0.22%
  • Veröffentlicht 05.10.2026 17:02:45
  • Zuletzt bearbeitet 06.10.2026 15:09:20

A flaw was found in Quay. A cross-site scripting (XSS) vulnerability in the OAuth callback handler allows a remote attacker to execute arbitrary JavaScript code within a user's browser session. By tricking a logged-in user into visiting a specially c...

  • EPSS 0.48%
  • Veröffentlicht 16.09.2026 21:02:29
  • Zuletzt bearbeitet 18.09.2026 19:06:08

A flaw was found in quay-builder-qemu. A remote attacker could exploit this by compromising the upstream `Noelware/docker-manifest-action` used in the release workflow, which is pinned to a mutable branch. This allows the attacker to inject arbitrary...

  • EPSS 0.13%
  • Veröffentlicht 14.08.2026 22:43:15
  • Zuletzt bearbeitet 20.08.2026 19:59:12

A flaw was found in Red Hat Quay. A user with FEATURE_BUILD_SUPPORT enabled and repository write access can exploit a Server-Side Request Forgery (SSRF) vulnerability within the build API. This allows the user to provide a malicious URL, causing the ...

  • EPSS 0.31%
  • Veröffentlicht 14.08.2026 22:43:10
  • Zuletzt bearbeitet 20.08.2026 20:05:07

A flaw was found in Red Hat Quay's exported logs feature. An unauthenticated attacker with a valid file ID could download exported action logs without proper authorization. While file IDs are complex, they can be intercepted from plaintext email or w...

  • EPSS 0.14%
  • Veröffentlicht 14.08.2026 22:43:06
  • Zuletzt bearbeitet 20.08.2026 20:01:38

A flaw was found in Red Hat Quay's Stripe billing webhook handler. This vulnerability allows an unauthenticated attacker to forge billing events by sending crafted JSON requests to the `/webhooks/stripe` endpoint without validating the Stripe-Signatu...

  • EPSS 0.26%
  • Veröffentlicht 14.08.2026 22:43:06
  • Zuletzt bearbeitet 20.08.2026 19:49:07

A flaw was found in Red Hat Quay. When the SECURITY_SCANNER_V4_PSK (pre-shared key) is not set, a remote unauthenticated attacker can send POST requests to the security scanner notification endpoint. This allows the attacker to flood the notification...

  • EPSS 0.26%
  • Veröffentlicht 14.08.2026 22:43:04
  • Zuletzt bearbeitet 20.08.2026 19:00:11

A flaw was found in Red Hat Quay. An administrator of any repository, by knowing or guessing a target notification's Universally Unique Identifier (UUID), can read the notification configuration, including sensitive details like webhook URLs, Slack t...

  • EPSS 0.18%
  • Veröffentlicht 14.08.2026 22:43:02
  • Zuletzt bearbeitet 20.08.2026 19:13:47

A flaw was found in Red Hat Quay's external Lightweight Directory Access Protocol (LDAP) authentication handling. When an LDAP referral is returned during authentication, the system does not properly escape the username input. This allows an attacker...