Home
MEDIUM: 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:NDefault status
unaffected
Any version before 3.11.11
affected
2.14.0 (semver) before 3.14.2
affected
3.12.0 (semver) before 3.12.10
affected
Default status
affected
Description
A flaw was found in Quay. When an organization acts as a proxy cache, and a user or robot pulls an image that hasn't been mirrored yet, they are granted "Admin" permissions on the newly created repository.
Problem types
Incorrect Privilege Assignment
Product status
Any version before 3.11.11
2.14.0 (semver) before 3.14.2
3.12.0 (semver) before 3.12.10
Timeline
| 2025-05-06: | Reported to Red Hat. |
| 2025-05-06: | Made public. |
References
access.redhat.com/security/cve/CVE-2025-4374
bugzilla.redhat.com/show_bug.cgi?id=2364267 (RHBZ#2364267)