A flaw was found in Red Hat Quay's custom build trigger handler. This vulnerability allows a user with organization repository administrative privileges and the FEATURE_BUILD_SUPPORT enabled to read arbitrary files on the build worker. This is possible due to insufficient validation of the build source configuration, which permits the use of a file:// Uniform Resource Identifier (URI) scheme. Exploiting this flaw can lead to unauthorized information disclosure.
Metrics
Affected Vendors & Products
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Tue, 29 Sep 2026 13:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A flaw was found in Red Hat Quay's custom build trigger handler. This vulnerability allows a user with organization repository administrative privileges and the FEATURE_BUILD_SUPPORT enabled to read arbitrary files on the build worker. This is possible due to insufficient validation of the build source configuration, which permits the use of a file:// Uniform Resource Identifier (URI) scheme. Exploiting this flaw can lead to unauthorized information disclosure. | |
| Title | quay: Local file inclusion via file:// scheme in Quay custom build trigger | |
| Weaknesses | CWE-918 | |
| References |
| |
| Metrics |
threat_severity
|
cvssV3_1
|
Projects
Sign in to view the affected projects.
No data.
No data.
No data.
OpenCVE Enrichment
No data.
Weaknesses