Impact
A flaw in Red Hat Quay’s custom build trigger handler, identified as a CWE-918 local file inclusion, allows an organization repository administrator with FEATURE_BUILD_SUPPORT enabled to read any file on the build worker by supplying a build source configuration that uses a file:// URI scheme. The insufficient validation of the build source configuration permits this local file inclusion, which can be used to exfiltrate confidential data from the build environment. The vulnerability requires legitimate administrative rights within the organization but still permits a malicious administrator to compromise information that should otherwise be protected.
Affected Systems
Red Hat Quay instances that enable custom build triggers. The affected product is the Quay custom build trigger handler; specific version numbers are not provided in the public data, so any deployment with this handler is potentially susceptible until a patch is applied.
Risk and Exploitability
The CVSS score of 7.7 indicates a high severity vulnerability. No EPSS score is available and the issue is not listed in CISA’s KEV catalog. The attack vector is likely local or within an organization, requiring repository administrative privileges. Because the flaw permits arbitrary file reads on the build worker, attackers with the necessary permissions could obtain sensitive configuration, credentials, or other secrets, leading to significant confidentiality impact.
OpenCVE Enrichment