CVE-2025-3528

A flaw was found in the Mirror Registry. The quay-app container shipped as part of the Mirror Registry for OpenShift has write access to the `/etc/passwd`. This flaw allows a malicious actor with access to the container to modify the passwd file and elevate their privileges to the root user within that pod.
Configurations

No configuration.

History

12 May 2025, 17:32

Type Values Removed Values Added
New CVE

Information

Published : 2025-05-09 12:15

Updated : 2025-05-12 17:32


NVD link : CVE-2025-3528

Mitre link : CVE-2025-3528

CVE.ORG link : CVE-2025-3528


JSON object : View

Products Affected

No product.

CWE
CWE-276

Incorrect Default Permissions