Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-10052

Опубликовано: 24 апр. 2026
Источник: redhat
CVSS3: 4.1
EPSS Низкий

Описание

A flaw was found in the Quay config-tool's LDAP and SMTP validation functions. An attacker with config editor access can exploit these functions, which make outbound connections to user-supplied endpoints without proper IP or host filtering. This allows the attacker to perform internal network reconnaissance from the Quay pod's network position, potentially mapping the internal network infrastructure.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Quay 3quay/quay-rhel8Fix deferred
Red Hat Quay 3quay/quay-rhel9Fix deferred

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-918
https://bugzilla.redhat.com/show_bug.cgi?id=2483157quay/config-tool: quay/config-tool: SSRF via unfiltered LDAP and SMTP config validation endpoints

EPSS

Процентиль: 8%
0.00186
Низкий

4.1 Medium

CVSS3

Связанные уязвимости

CVSS3: 4.1
nvd
3 месяца назад

A flaw was found in the Quay config-tool's LDAP and SMTP validation functions. An attacker with config editor access can exploit these functions, which make outbound connections to user-supplied endpoints without proper IP or host filtering. This allows the attacker to perform internal network reconnaissance from the Quay pod's network position, potentially mapping the internal network infrastructure.

CVSS3: 4.1
github
3 месяца назад

A flaw was found in the Quay config-tool's LDAP and SMTP validation functions. An attacker with config editor access can exploit these functions, which make outbound connections to user-supplied endpoints without proper IP or host filtering. This allows the attacker to perform internal network reconnaissance from the Quay pod's network position, potentially mapping the internal network infrastructure.

EPSS

Процентиль: 8%
0.00186
Низкий

4.1 Medium

CVSS3