Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-2377

Опубликовано: 08 апр. 2026
Источник: redhat
CVSS3: 6.5

Описание

A flaw was found in Red Hat Quay and mirror registry for Red Hat OpenShift. The log export feature in these products allows an authenticated user to specify an arbitrary callback URL. A backend process then makes server-side HTTP requests to this provided URL. This vulnerability, known as Server-Side Request Forgery (SSRF), could allow an attacker to send requests from the application's internal network, potentially leading to the disclosure of sensitive information.

Отчет

Due to the intended and supported use case of Openshift Mirror Registry, deployment in an offline or network-isolated environment, the impact for this product has been downgraded to Moderate. Even in case of compromise, the blast radius is restricted to mirror-registry. It can not be escalated outside the core product. This vulnerability has been scored based on the lack of change of scope.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
mirror registry for Red Hat OpenShiftopenshift/mirror-registry-rhel8Fix deferred
mirror registry for Red Hat OpenShift 2openshift/mirror-registry-rhel8Fix deferred
Red Hat Quay 3.10quay/quay-rhel8FixedRHSA-2026:2284003.06.2026
Red Hat Quay 3.12quay/quay-rhel8FixedRHSA-2026:2262902.06.2026
Red Hat Quay 3.14quay/quay-rhel8FixedRHSA-2026:2101726.05.2026
Red Hat Quay 3.15quay/quay-rhel8FixedRHSA-2026:2485309.06.2026
Red Hat Quay 3.16quay/quay-rhel9FixedRHSA-2026:1937519.05.2026
Red Hat Quay 3.9quay/quay-rhel8FixedRHSA-2026:2336104.06.2026

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-918
https://bugzilla.redhat.com/show_bug.cgi?id=2439201mirror-registry: quay: quay: Server-Side Request Forgery via log export functionality

6.5 Medium

CVSS3

Связанные уязвимости

CVSS3: 6.5
nvd
4 месяца назад

A flaw was found in Red Hat Quay and mirror registry for Red Hat OpenShift. The log export feature in these products allows an authenticated user to specify an arbitrary callback URL. A backend process then makes server-side HTTP requests to this provided URL. This vulnerability, known as Server-Side Request Forgery (SSRF), could allow an attacker to send requests from the application's internal network, potentially leading to the disclosure of sensitive information.

CVSS3: 6.5
github
4 месяца назад

A flaw was found in mirror-registry. Authenticated users can exploit the log export feature by providing a specially crafted web address (URL). This allows the application's backend to make arbitrary requests to internal network resources, a vulnerability known as Server-Side Request Forgery (SSRF). This could lead to unauthorized access to sensitive information or other internal systems.

6.5 Medium

CVSS3