Mitigating the LUCKY13 Vulnerability (Weak CBC Ciphers) in Red Hat Quay on OpenShift

Solution Unverified - Updated -

Issue

  • Security vulnerability scans (e.g., Burp Suite, Nessus) report that the Quay registry URL is vulnerable to the LUCKY13 attack (CVE-2013-0169)
    or exposes weak Cipher Block Chaining (CBC) ciphers.

  • The OpenShift cluster's Ingress Controller is already configured to enforce strong ciphers, but the Quay registry URL continues to expose weak
    ciphers.

  • Attempting to fix the issue by setting EXTERNAL_TLS_TERMINATION: true in the Quay config.yaml while maintaining a passthrough route
    causes the Quay pods to fail health checks and get stuck in a 0/1 pending/crashing state.

Environment

  • Red Hat Quay (v3.x)
  • Quay deployed via the Red Hat Quay Operator
  • Red Hat OpenShift Container Platform (OCP)
  • Quay OpenShift Route configured for TLS passthrough termination

Subscriber exclusive content

A Red Hat subscription provides unlimited access to our knowledgebase, tools, and much more.

Current Customers and Partners

Log in for full access

Log In

New to Red Hat?

Learn more about Red Hat subscriptions

Using a Red Hat product through a public cloud?

How to access this content