CVE-2025-4374

A flaw was found in Quay. When an organization acts as a proxy cache, and a user or robot pulls an image that hasn't been mirrored yet, they are granted "Admin" permissions on the newly created repository.
Configurations

No configuration.

History

07 May 2025, 14:13

Type Values Removed Values Added
Summary
  • (es) Se detectó una falla en Quay. Cuando una organización actúa como caché proxy y un usuario o robot extrae una imagen que aún no se ha replicado, se le otorgan permisos de administrador en el repositorio recién creado.

06 May 2025, 15:16

Type Values Removed Values Added
New CVE

Information

Published : 2025-05-06 15:16

Updated : 2025-05-07 14:13


NVD link : CVE-2025-4374

Mitre link : CVE-2025-4374

CVE.ORG link : CVE-2025-4374


JSON object : View

Products Affected

No product.

CWE
CWE-266

Incorrect Privilege Assignment