Impact
A flaw was discovered in the quay-builder-qemu component of Red Hat Quay 3. The release workflow calls a third‑party GitHub Action, Noelware/docker-manifest-action, pinned to the mutable @master branch. An attacker who can compromise that upstream action—by inserting malicious code into it or by controlling the branch—can cause the action to execute arbitrary commands during the build. This gives the attacker the ability to exfiltrate registry credentials, use the exposed default GitHub token, or publish malicious container images. The weakness is reflected by CWE‑1357, which involves insecure handling of external components.
Affected Systems
The vulnerability is present in Red Hat Quay 3, specifically when the quay-builder-qemu release workflow is used as shipped by Red Hat. All installations that rely on the default workflow with the Noelware/docker-manifest-action pinned to @master are affected; the affected product is Red Hat Quay 3. No specific patch version is provided in the CVE, so all current releases that use this workflow remain vulnerable until Red Hat publishes a fix.
Risk and Exploitability
The CVSS base score of 8 signals a high threat, but the EPSS score of less than 1 % suggests that exploitation is currently rare and no known exploits have been observed, and the vulnerability is not yet listed in the CISA KEV catalog. Even with the low current exploitation probability, the ability to inject code that runs under the build environment and to harvest sensitive credentials means that a successful attack could give an attacker full control of the container registry used by the organization. The attack likely requires a compromise of the upstream action repository or an invitation to contribute to it, but because the action is pinned to a mutable branch, any such compromise will automatically affect all future releases. No official workaround is available; an inbound update or configuration change is needed to prevent the attack.
OpenCVE Enrichment