Bug 2446750 (CVE-2026-31959)
| Summary: | CVE-2026-31959 github.com/anchore/quill: Quill: Sensitive data exfiltration via Server-Side Request Forgery (SSRF) | ||
|---|---|---|---|
| Product: | [Other] Security Response | Reporter: | OSIDB Bzimport <bzimport> |
| Component: | vulnerability | Assignee: | Product Security DevOps Team <prodsec-dev> |
| Status: | NEW --- | QA Contact: | |
| Severity: | medium | Docs Contact: | |
| Priority: | medium | ||
| Version: | unspecified | CC: | agarcial, aoconnor, asegurap, jburrell |
| Target Milestone: | --- | Keywords: | Security |
| Target Release: | --- | ||
| Hardware: | All | ||
| OS: | Linux | ||
| Whiteboard: | |||
| Fixed In Version: | Doc Type: | --- | |
| Doc Text: |
A flaw was found in Quill. This Server-Side Request Forgery (SSRF) vulnerability occurs when Quill attempts to fetch Apple notarization submission logs. An attacker, capable of tampering with API responses from Apple's notarization service (e.g., in environments with TLS-intercepting proxies), can supply a malicious URL. This causes the Quill client to make requests to arbitrary internal or external network destinations, potentially leading to the exfiltration of sensitive data such as cloud provider credentials or internal service responses.
|
Story Points: | --- |
| Clone Of: | Environment: | ||
| Last Closed: | Type: | --- | |
| Regression: | --- | Mount Type: | --- |
| Documentation: | --- | CRM: | |
| Verified Versions: | Category: | --- | |
| oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
| Cloudforms Team: | --- | Target Upstream Version: | |
| Embargoed: | |||
|
Description
OSIDB Bzimport
2026-03-11 20:01:24 UTC
|