CyberRota Analysis
AI-GeneratedA Server-Side Request Forgery (SSRF) vulnerability exists in Red Hat Quay, allowing users with FEATURE_BUILD_SUPPORT enabled and repository write access to exploit the build API. This flaw enables the submission of malicious URLs, potentially exposing sensitive internal information by allowing the Quay builder to make unauthorized requests to internal network addresses. Organizations using Red Hat Quay should prioritize addressing this vulnerability to mitigate risks associated with internal data exposure.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
A flaw was found in Red Hat Quay. A user with FEATURE_BUILD_SUPPORT enabled and repository write access can exploit a Server-Side Request Forgery (SSRF) vulnerability within the build API. This allows the user to provide a malicious URL, causing the Quay builder to make requests to internal network addresses. Such an action could lead to the disclosure of sensitive internal information.