Redhat

Quay

52 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.19%
  • Veröffentlicht 14.08.2026 22:43:01
  • Zuletzt bearbeitet 20.08.2026 19:45:42

A flaw was found in Red Hat Quay's JWT (JSON Web Token) validation for federated robot accounts and single sign-on (SSO) authentication. Multiple issues related to audience verification and the enforcement of `azp` and `sub` claims were identified. T...

  • EPSS 0.27%
  • Veröffentlicht 11.08.2026 07:39:56
  • Zuletzt bearbeitet 14.08.2026 19:07:46

A flaw was found in claircore's RPM package scanner. Crafted RPM header data in a container layer can cause an unchecked type assertion to panic the scanner. The panic is not recovered, causing the Clair indexer process to crash, leading to a denial ...

  • EPSS 0.27%
  • Veröffentlicht 29.07.2026 16:34:44
  • Zuletzt bearbeitet 01.10.2026 17:17:22

A flaw was found in Quay. A user configured in GLOBAL_READONLY_SUPER_USERS is able to view robot account tokens for repositories they are not a member of, allowing an attacker with read-only superuser privileges to impersonate any robot account.

  • EPSS 0.29%
  • Veröffentlicht 21.07.2026 04:45:27
  • Zuletzt bearbeitet 22.09.2026 18:17:10

A flaw was found in Red Hat Quay's repository-level mirror configuration feature. The POST and PUT handlers in endpoints/api/mirror.py accept an external_reference parameter without SSRF validation, unlike the organization-level mirror handlers which...

Exploit
  • EPSS 0.78%
  • Veröffentlicht 11.06.2026 15:33:12
  • Zuletzt bearbeitet 11.09.2026 13:18:08

Axios is a promise based HTTP client for the browser and Node.js. From 0.19.0 to before 0.31.1 and 1.15.2, Axios contains prototype-pollution gadgets in request config processing. If another vulnerability in the same JavaScript process has already po...

  • EPSS 0.14%
  • Veröffentlicht 08.06.2026 10:54:40
  • Zuletzt bearbeitet 23.07.2026 07:10:00

A flaw was found in Quay. The filedrop endpoint accepts any mime type without validation, allowing an authenticated user with repository write access to upload a malicious SVG file containing JavaScript. The file is stored and served inline through t...

  • EPSS 0.29%
  • Veröffentlicht 01.06.2026 09:16:16
  • Zuletzt bearbeitet 27.07.2026 09:16:37

Rejected reason: Retracted following review by Red Hat Product Security and confirmation from the upstream Clair/Claircore maintainer. This CVE misattributes the described behavior to github.com/quay/claircore: the authentication mechanism in questio...

  • EPSS 0.2%
  • Veröffentlicht 29.05.2026 09:30:30
  • Zuletzt bearbeitet 21.07.2026 12:10:00

A flaw was found in the Quay config-tool's GitLab OAuth validator. This vulnerability causes sensitive credentials, specifically client_id and client_secret, to be transmitted as plaintext in URL query parameters during POST requests to the GitLab en...

  • EPSS 0.19%
  • Veröffentlicht 29.05.2026 07:59:20
  • Zuletzt bearbeitet 21.07.2026 12:10:00

A flaw was found in the Quay config-tool's LDAP and SMTP validation functions. An attacker with config editor access can exploit these functions, which make outbound connections to user-supplied endpoints without proper IP or host filtering. This all...

  • EPSS 0.26%
  • Veröffentlicht 22.04.2026 09:06:19
  • Zuletzt bearbeitet 20.05.2026 13:38:24

A flaw was found in Red Hat Quay. When Red Hat Quay requests password re-verification for sensitive operations, such as token generation or robot account creation, the re-authentication prompt can be bypassed. This allows a user with a timed-out sess...