Beveiligingsadvies

CVE-2026-10052

CVE-kwetsbaarheidsdetails - eXtreme Datacenter Security Operations

Gepubliceerd 2026-05-29 07:59:20
Laatst bijgewerkt 2026-05-29 16:23:34
Toegewezen door redhat
CVSS-score 4.1
Status PUBLISHED

Beschrijving

A flaw was found in the Quay config-tool's LDAP and SMTP validation functions. An attacker with config editor access can exploit these functions, which make outbound connections to user-supplied endpoints without proper IP or host filtering. This allows the attacker to perform internal network reconnaissance from the Quay pod's network position, potentially mapping the internal network infrastructure.