Impact
Quay’s Stripe webhook handler lacks signature verification, allowing an unauthenticated attacker to send forged JSON messages to the /webhooks/stripe endpoint. The flaw enables the attacker to reset a namespace’s build quota to its maximum value and trigger unsolicited billing notifications to namespace administrators. This can lead to unexpected cost increases and administrative confusion, particularly in environments where billing data drives operational decisions.
Affected Systems
The vulnerability affects Red Hat Quay version 3 and is also listed against Red Hat OpenShift Update Service. No specific sub‑versions are enumerated, so all instances of Quay 3 are considered vulnerable.
Risk and Exploitability
The CVSS score of 5.9 classifies the flaw as moderate severity, and the EPSS score is unavailable, indicating no quantified exploitation frequency. The vulnerability can be leveraged remotely; any host able to reach the public /webhooks/stripe endpoint can send crafted requests, bypassing authentication entirely. The flaw is not listed in CISA’s KEV catalog, but the lack of validation makes it trivially exploitable without additional privileges.
OpenCVE Enrichment