Impact
A flaw in Red Hat Quay allows an attacker to send unauthenticated POST requests to the security scanner notification endpoint when the SECURITY_SCANNER_V4_PSK is not configured. This can drain worker resources and inject path‑traversal characters into the Clair API URL, causing blind path manipulation on the Clair host. The result is service disruption and a denial of service for the affected registry services.
Affected Systems
The vulnerability affects Red Hat Quay version 3 and is also referenced in the Red Hat OpenShift Update Service. No specific version range is provided beyond the Quay 3 designation; organizations running this component should review their configuration to ensure the PSK is set.
Risk and Exploitability
The CVSS base score of 6.5 indicates a moderate impact, while the EPSS score is unavailable and the issue is not included in the CISA KEV catalog, suggesting limited current exploitation data. However, the described attack vector is an unauthenticated remote POST to an exposed endpoint, meaning an attacker with network reach could trigger the flaw without authentication. Because the impact can lead to denial of service, the risk remains significant for any exposed Quay installation lacking a pre‑shared key.
OpenCVE Enrichment