HIGH🇬🇧 English

CVE-2026-32589

CVSS 7.4v3.1pub. 2026-04-08upd. 2026-08-17

A flaw was found in Red Hat Quay's container image upload process. An authenticated user with push access to any repository on the registry can interfere with image uploads in progress by other users, including those in repositories they do not have access to. This could allow the attacker to read, modify, or cancel another user's in-progress image upload.

oryginał EN
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:L
  • Red Hat Mirror Registry For Red Hat Openshift

    APP
    Redhat
    2.0
  • Red Hat Quay

    APP
    Redhat
    3.0.0
🔵
ZWERYFIKUJ U PRODUCENTA
Brak jednoznacznych danych o patchu. Sprawdź referencje od producenta.
Tagi
Container
CWE
Referencje

Powiązane podatności

CVE-2021-3762CRITICAL9.8PL ✓ten sam produkt

Path Traversal w ClairCore umożliwiający zapis plików i RCE

CVE-2020-27832CRITICAL9.0PL ✓ten sam produkt

Persistent XSS w Red Hat Quay – powiadomienia repozytoriów

CVE-2026-44495HIGH7.0ten sam produkt

Axios is a promise based HTTP client for the browser and Node.js. From 0.19.0 to before 0.31.1 and 1.15.2, Axi...

CVE-2026-32590HIGH7.1ten sam produkt

A flaw was found in Red Hat Quay's handling of resumable container image layer uploads. The upload process sto...

CVE-2020-10735HIGH7.5ten sam produkt

A flaw was found in python. In algorithms with quadratic time complexity using non-binary bases, when using in...