Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2025-4374

Опубликовано: 06 мая 2025
Источник: redhat
CVSS3: 6.5
EPSS Низкий

Описание

A flaw was found in Quay. When an organization acts as a proxy cache, and a user or robot pulls an image that hasn't been mirrored yet, they are granted "Admin" permissions on the newly created repository.

Меры по смягчению последствий

Permissions can be updated after creation but there's no preventative measure before hand.

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-266
https://bugzilla.redhat.com/show_bug.cgi?id=2364267quay: Incorrect Privilege Assignment

EPSS

Процентиль: 25%
0.00322
Низкий

6.5 Medium

CVSS3

Связанные уязвимости

CVSS3: 6.5
nvd
больше 1 года назад

A flaw was found in Quay. When an organization acts as a proxy cache, and a user or robot pulls an image that hasn't been mirrored yet, they are granted "Admin" permissions on the newly created repository.

CVSS3: 6.5
github
больше 1 года назад

A flaw was found in Quay. When an organization acts as a proxy cache, and a user or robot pulls an image that hasn't been mirrored yet, they are granted "Admin" permissions on the newly created repository.

EPSS

Процентиль: 25%
0.00322
Низкий

6.5 Medium

CVSS3