REDHAT-BUG-2446965: SSRF
A Server-Side Request Forgery (SSRF) vulnerability was identified in Red Hat Quay v3.12.x within the Proxy Cache configuration feature. An authenticated organization administrator can supply an attacker-controlled hostname as the upstreamregistry parameter when creating or validating a proxy cache configuration. Quay instantiates a network connection to the supplied hostname with no validation against internal address ranges, private IP space, or cloud metadata endpoints.
Requirements to exploit: Attacker needs to be logged into the web app / initiate podman execution from host.
Component affected: Mirror Registry for OpenShift – Proxy Cache configuration feature Quay deployed on OpenShift 4.20 – Proxy Cache configuration feature
Version affected: latest releases
Affected Software
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-2446965?
The severity of REDHAT-BUG-2446965 is classified as high with a score of 7.
How do I fix REDHAT-BUG-2446965?
To address REDHAT-BUG-2446965, ensure you update Red Hat Quay to the latest version provided by Red Hat.
What type of vulnerability is REDHAT-BUG-2446965?
REDHAT-BUG-2446965 is identified as a Server-Side Request Forgery (SSRF) vulnerability.
Who is affected by REDHAT-BUG-2446965?
REDHAT-BUG-2446965 affects authenticated organization administrators using Red Hat Quay v3.12.x.
What configuration feature is involved in REDHAT-BUG-2446965?
The Proxy Cache configuration feature is involved in the REDHAT-BUG-2446965 vulnerability.