Red Hat Quay是美国红帽(Red Hat)公司的一个容器镜像仓库平台。 Red Hat Quay存在安全漏洞,该漏洞源于GitLab OAuth验证器将敏感凭据以明文形式传输到URL查询参数中,可能导致凭据泄露。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Red Hat | Red Hat Quay 3 | any |
affected |
any |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Red Hat | Red Hat Quay 3 | - |
cpe:/a:redhat:quay:3
|
|
| Red Hat | Red Hat Quay 3 | - |
cpe:/a:redhat:quay:3
|
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-42965 | 7.7 HIGH | Openshift/router: openshift/router: cloud metadata ssrf via fqdn-typed endpointslice bypas |
| CVE-2026-46579 | 7.4 HIGH | Openshift/router: openshift/router: mtls client certificate spoofing via unstripped x-ssl- |
| CVE-2026-10101 | 6.3 MEDIUM | Assisted-service: assisted-service: infraenv status leaks referenced pull-secret contents |
| CVE-2026-6324 | 4.8 MEDIUM | Libsoup: libsoup: http request smuggling via unsigned to signed conversion error |
| CVE-2026-10052 | 4.1 MEDIUM | Quay/config-tool: quay/config-tool: ssrf via unfiltered ldap and smtp config validation en |
No comments yet