Red Hat Quay是美国红帽(Red Hat)公司的一款分布式容器镜像仓库,它主要用于构建、分布和部署容器。 Red Hat Quay存在代码问题漏洞,该漏洞源于Proxy Cache配置功能未验证上游注册表主机名,可能导致具有组织管理员权限的攻击者强制服务器向内部网络服务发起请求。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Red Hat | mirror registry for Red Hat OpenShift | any |
affected |
| Red Hat | mirror registry for Red Hat OpenShift 2 | any |
affected |
| Red Hat | Red Hat Quay 3.10 | 1783750447< * |
unaffected |
| Red Hat | Red Hat Quay 3.12 | 1783751865< * |
unaffected |
1784353904< * |
unaffected | ||
| Red Hat | Red Hat Quay 3.14 | 1788593843< * |
unaffected |
| Red Hat | Red Hat Quay 3.15 | 1784351966< * |
unaffected |
| Red Hat | Red Hat Quay 3.16 | 1783955846< * |
unaffected |
| Red Hat | Red Hat Quay 3.17 | 1780604033< * |
unaffected |
| Red Hat | Red Hat Quay 3.18 | 1784987273< * |
unaffected |
| Red Hat | Red Hat Quay 3.9 | 1784125838< * |
unaffected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Red Hat | Red Hat Quay 3.10 | 1783750447 ~ * |
cpe:/a:redhat:quay:3.10::el8
|
|
| Red Hat | Red Hat Quay 3.12 | 1783751865 ~ * |
cpe:/a:redhat:quay:3.12::el8
|
|
| Red Hat | Red Hat Quay 3.12 | 1784353904 ~ * |
cpe:/a:redhat:quay:3.12::el8
|
|
| Red Hat | Red Hat Quay 3.14 | 1788593843 ~ * |
cpe:/a:redhat:quay:3.14::el8
|
|
| Red Hat | Red Hat Quay 3.15 | 1784351966 ~ * |
cpe:/a:redhat:quay:3.15::el8
|
|
| Red Hat | Red Hat Quay 3.16 | 1783955846 ~ * |
cpe:/a:redhat:quay:3.16::el9
|
|
| Red Hat | Red Hat Quay 3.17 | 1780604033 ~ * |
cpe:/a:redhat:quay:3.17::el9
|
|
| Red Hat | Red Hat Quay 3.18 | 1784987273 ~ * |
cpe:/a:redhat:quay:3.18::el9
|
|
| Red Hat | Red Hat Quay 3.9 | 1784125838 ~ * |
cpe:/a:redhat:quay:3.9::el8
|
|
| Red Hat | mirror registry for Red Hat OpenShift | - |
cpe:/a:redhat:mirror_registry:1
|
|
| Red Hat | mirror registry for Red Hat OpenShift 2 | - |
cpe:/a:redhat:mirror_registry:2
|
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-32589 | 7.4 HIGH | Mirror-registry: quay: insecure direct object reference in blobupload |
| CVE-2026-32590 | 7.1 HIGH | Mirror-registry: remote code execution using pickle deserialization |
| CVE-2026-2377 | 6.5 MEDIUM | Mirror-registry: quay: quay: server-side request forgery via log export functionality |
| CVE-2025-57851 | 6.4 MEDIUM | Mce: privilege escalation via excessive /etc/passwd permissions |
| CVE-2025-57847 | 6.4 MEDIUM | Ansible-automation-platform: privilege escalation via excessive group writable /etc/passwd |
| CVE-2025-57854 | 6.4 MEDIUM | Osus-operator: privilege escalation via excessive /etc/passwd permissions |
| CVE-2025-57853 | 6.4 MEDIUM | Web-terminal: privilege escalation via excessive /etc/passwd permissions |
| CVE-2025-58713 | 6.4 MEDIUM | Rhpam: privilege escalation via excessive /etc/passwd permissions |
| CVE-2025-14243 | 5.3 MEDIUM | Mirror-registry: openshift mirror registry: user enumeration via authentication error mess |
No comments yet