Mitigating the LUCKY13 Vulnerability (Weak CBC Ciphers) in Red Hat Quay on OpenShift
Issue
-
Security vulnerability scans (e.g., Burp Suite, Nessus) report that the Quay registry URL is vulnerable to the LUCKY13 attack (CVE-2013-0169)
or exposes weak Cipher Block Chaining (CBC) ciphers. -
The OpenShift cluster's Ingress Controller is already configured to enforce strong ciphers, but the Quay registry URL continues to expose weak
ciphers. -
Attempting to fix the issue by setting EXTERNAL_TLS_TERMINATION: true in the Quay config.yaml while maintaining a passthrough route
causes the Quay pods to fail health checks and get stuck in a 0/1 pending/crashing state.
Environment
- Red Hat Quay (v3.x)
- Quay deployed via the Red Hat Quay Operator
- Red Hat OpenShift Container Platform (OCP)
- Quay OpenShift Route configured for TLS passthrough termination
Subscriber exclusive content
A Red Hat subscription provides unlimited access to our knowledgebase, tools, and much more.