Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-h9q8-x6vm-q57f

Опубликовано: 29 мая 2026
Источник: github
Github: Не прошло ревью
CVSS3: 4.1

Описание

A flaw was found in the Quay config-tool's LDAP and SMTP validation functions. An attacker with config editor access can exploit these functions, which make outbound connections to user-supplied endpoints without proper IP or host filtering. This allows the attacker to perform internal network reconnaissance from the Quay pod's network position, potentially mapping the internal network infrastructure.

A flaw was found in the Quay config-tool's LDAP and SMTP validation functions. An attacker with config editor access can exploit these functions, which make outbound connections to user-supplied endpoints without proper IP or host filtering. This allows the attacker to perform internal network reconnaissance from the Quay pod's network position, potentially mapping the internal network infrastructure.

EPSS

Процентиль: 8%
0.00186
Низкий

4.1 Medium

CVSS3

Дефекты

CWE-918

Связанные уязвимости

CVSS3: 4.1
redhat
4 месяца назад

A flaw was found in the Quay config-tool's LDAP and SMTP validation functions. An attacker with config editor access can exploit these functions, which make outbound connections to user-supplied endpoints without proper IP or host filtering. This allows the attacker to perform internal network reconnaissance from the Quay pod's network position, potentially mapping the internal network infrastructure.

CVSS3: 4.1
nvd
3 месяца назад

A flaw was found in the Quay config-tool's LDAP and SMTP validation functions. An attacker with config editor access can exploit these functions, which make outbound connections to user-supplied endpoints without proper IP or host filtering. This allows the attacker to perform internal network reconnaissance from the Quay pod's network position, potentially mapping the internal network infrastructure.

EPSS

Процентиль: 8%
0.00186
Низкий

4.1 Medium

CVSS3

Дефекты

CWE-918