Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-74240

Опубликовано: 14 авг. 2026
Источник: redhat
CVSS3: 5.4
EPSS Низкий

Описание

A flaw was found in Red Hat Quay's JWT (JSON Web Token) validation for federated robot accounts and single sign-on (SSO) authentication. Multiple issues related to audience verification and the enforcement of azp and sub claims were identified. These flaws could allow an attacker with a validly-signed token from the same identity provider to bypass configured security restrictions. This bypass could lead to unauthorized access by circumventing intended audience, subject, or authorized-client limitations.

Отчет

This Moderate impact flaw in Red Hat Quay allows an attacker with a validly-signed token from the same identity provider to bypass configured audience, subject, or authorized-client restrictions. This is due to default configurations for federated robot authentication not enforcing audience verification, and insufficient checks for 'azp' and 'sub' claims in certain scenarios. Exploitation requires a pre-existing valid token from the same IdP, limiting the attack surface.

Меры по смягчению последствий

To mitigate this issue, Red Hat Quay administrators should ensure that federated robot authentication is configured with specific audiences to enable 'verify_aud' enforcement. Additionally, review and update existing federation configurations to explicitly include and enforce 'azp' and 'sub' claims, preventing bypasses when these claims are absent. Refer to Red Hat Quay documentation for detailed configuration steps. A restart of affected Quay services may be required after configuration changes.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat OpenShift Update Serviceopenshift-update-service/openshift-update-service-rhel8Fix deferred
Red Hat Quay 3quay/quay-rhel8Fix deferred
Red Hat Quay 3quay/quay-rhel9Fix deferred

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-287
https://bugzilla.redhat.com/show_bug.cgi?id=2516139quay: JWT claim validation bypasses in Quay federated robot and SSO authentication

EPSS

Процентиль: 7%
0.00173
Низкий

5.4 Medium

CVSS3

Связанные уязвимости

CVSS3: 5.4
nvd
17 дней назад

A flaw was found in Red Hat Quay's JWT (JSON Web Token) validation for federated robot accounts and single sign-on (SSO) authentication. Multiple issues related to audience verification and the enforcement of `azp` and `sub` claims were identified. These flaws could allow an attacker with a validly-signed token from the same identity provider to bypass configured security restrictions. This bypass could lead to unauthorized access by circumventing intended audience, subject, or authorized-client limitations.

CVSS3: 5.4
github
17 дней назад

A flaw was found in Red Hat Quay's JWT (JSON Web Token) validation for federated robot accounts and single sign-on (SSO) authentication. Multiple issues related to audience verification and the enforcement of `azp` and `sub` claims were identified. These flaws could allow an attacker with a validly-signed token from the same identity provider to bypass configured security restrictions. This bypass could lead to unauthorized access by circumventing intended audience, subject, or authorized-client limitations.

EPSS

Процентиль: 7%
0.00173
Низкий

5.4 Medium

CVSS3