REDHAT-BUG-2545916: Medium severity Red Hat Quay vulnerability
A flaw was found in Quay's build trigger API endpoints. The BuildTriggerList.get and BuildTrigger.get handlers in endpoints/api/trigger.py hardcode canadmin=True when serializing trigger data via the triggerview function, regardless of whether the caller is a full administrator or a global read-only superuser. This causes the trigger configuration, including delegate write tokens embedded in webhook endpoint URLs, to be exposed to users in the GLOBALREADONLYSUPERUSERS list. These delegate tokens carry push scope for the repository and can be used to push arbitrary container images to private repositories, bypassing the read-only restriction of the caller's role.
Affected Software
Event History
Frequently Asked Questions
Which users can access the exposed trigger configuration?
Users listed in GLOBAL_READONLY_SUPER_USERS can receive trigger configuration data even though they are intended to have read-only global access.
What does an attacker need to exploit this issue?
An attacker needs access as a global read-only superuser and access to the affected build trigger API endpoints. The exposed webhook URLs include delegate write tokens.
What can be done with an exposed delegate token?
The token has push scope for the associated repository and can be used to push arbitrary container images to private repositories. This bypasses the read-only restriction of the user who obtained it.
How can administrators determine whether they may be exposed?
Review whether any users are configured in GLOBAL_READONLY_SUPER_USERS and whether build triggers are configured for private repositories. Those users may be able to retrieve trigger configuration containing repository write tokens.