CVE-2025-3528

A flaw was found in the Mirror Registry. The quay-app container shipped as part of the Mirror Registry for OpenShift has write access to the `/etc/passwd`. This flaw allows a malicious actor with access to the container to modify the passwd file and elevate their privileges to the root user within that pod.
CVSS

No CVSS.

Configurations

No configuration.

History

14 Aug 2025, 18:15

Type Values Removed Values Added
References
  • () https://access.redhat.com/errata/RHBA-2025:9645 -
CVSS v2 : unknown
v3 : 8.2
v2 : unknown
v3 : unknown
CWE CWE-276

09 May 2025, 12:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-05-09 12:15

Updated : 2025-08-14 18:15


NVD link : CVE-2025-3528

Mitre link : CVE-2025-3528


JSON object : View

Products Affected

No product.

CWE

No CWE.