Impact
A flaw in Quay allows an authenticated read‑only administrator to retrieve repository write tokens through the build trigger API. By exposing these delegate tokens, the attacker can bypass read‑only restrictions and push arbitrary container images to private repositories, effectively raising the attacker’s privilege level within the system.
Affected Systems
Red Hat Quay 3 (no specific version information is provided).
Risk and Exploitability
The vulnerability has a moderate CVSS score of 5.5 and is not currently listed in the CISA KEV catalog, with no EPSS score available. The exploit requires an authenticated read‑only superuser with access to the build trigger endpoint; an attacker can call this API, harvest the write tokens, and push images. The lack of proper authorization checks (CWE‑863) makes the attack straightforward once credentials are obtained.
OpenCVE Enrichment