Impact
A flaw in Red Hat Quay allows a user who has write access to a repository and the FEATURE_BUILD_SUPPORT capability enabled to supply an arbitrary URL to the build API. The Quay builder will then issue an HTTP request to the supplied URL, potentially reaching internal network services and revealing sensitive information. The weakness is a server‑side request forgery as classified by CWE‑918.
Affected Systems
Red Hat Quay 3 and Red Hat OpenShift Update Service 5 are affected. The CVE does not specify particular sub‑versions or patch levels beyond the product name.
Risk and Exploitability
The CVSS score is 4.2, indicating low overall severity. No EPSS data is available and the vulnerability is not listed in the CISA KEV catalog. Exploitation requires that the attacker possess write permission on the repository and that FEATURE_BUILD_SUPPORT be enabled, limiting the attack surface. The risk is therefore moderate within those constraints, but the potential for internal data disclosure remains if the exploit is successful.
OpenCVE Enrichment