
We found results for “”
CVE-2025-4374
Good to know:

Date: May 6, 2025
A flaw was found in Quay. When an organization acts as a proxy cache, and a user or robot pulls an image that hasn't been mirrored yet, they are granted "Admin" permissions on the newly created repository.
Severity Score
Severity Score
Weakness Type (CWE)
Incorrect Privilege Assignment
CWE-266Top Fix

Upgrade Version
Upgrade to version https://github.com/quay/quay.git - null
CVSS v3.1
Base Score: |
|
---|---|
Attack Vector (AV): | NETWORK |
Attack Complexity (AC): | LOW |
Privileges Required (PR): | NONE |
User Interaction (UI): | NONE |
Scope (S): | UNCHANGED |
Confidentiality (C): | LOW |
Integrity (I): | LOW |
Availability (A): | NONE |