在 Quay 中发现了一个缺陷。在处理构建触发请求时,应用程序错误地向全局只读管理用户暴露了包含仓库写入令牌(repository write tokens)的触发器配置详情。具有只读权限的经过身份验证的用户可以通过查询构建触发器 API 来检索这些委托令牌,从而利用此漏洞。该问题使得受限制的用户能够绕过只读限制,向私有仓库推送任意的容器镜像,从而导致权限提升(privilege escalation)。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Red Hat | Red Hat Quay 3 | - |
cpe:/a:redhat:quay:3
|
|
| Red Hat | Red Hat Quay 3 | - |
cpe:/a:redhat:quay:3
|
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-101919 | 8.8 HIGH | Hypershift: hypershift: unsanitized kubeconfig passthrough from tenant namespace to contro |
| CVE-2026-71299 | 6.5 MEDIUM | Maestro: maestro: rest api write endpoints registered without authentication middleware |
| CVE-2026-105306 | 6.5 MEDIUM | Keycloak-services: keycloak-services: token introspection audience bypass via dynamic clie |
| CVE-2026-71298 | 6.4 MEDIUM | Maestro: sql identifier injection via properties.* search filter and orderby field |
| CVE-2026-105302 | 5.7 MEDIUM | Keycloak-services: keycloak-services: user session note mapper exposes upstream idp access |
| CVE-2026-104030 | 5.5 MEDIUM | Sssd: sssd: denial of service via out-of-bounds read during passkey parsing |
| CVE-2026-71297 | 5.4 MEDIUM | Maestro: maestro: grpc broker has no auth interceptor and client mtls is optional |
| CVE-2026-102295 | 5.4 MEDIUM | Quay: quay: dom-based cross-site scripting via oauth local callback format=json parameter |
| CVE-2026-102576 | 4.2 MEDIUM | Quay: quay: dom-based cross-site scripting via unvalidated redirect_url on signin page |
| CVE-2026-105301 | 4.0 MEDIUM | Keycloak-services: keycloak-services: blind ssrf via x.509 authenticator fetching attacker |
| CVE-2026-104029 | 3.3 LOW | Sssd: sssd: denial of service via out-of-bounds read in autofs responder |
| CVE-2026-105326 | 2.5 LOW | Cups: cups: argument injection in mailto notifier via notify-recipient-uri |
No comments yet