CVE-2025-4374
published 2025-05-06CVE-2025-4374: A flaw was found in Quay. When an organization acts as a proxy cache, and a user or robot pulls an image that hasn't been mirrored yet, they are granted…
PriorityP432medium6.5CVSS 3.1
AVNACLPRNUINSUCLILAN
EPSS
0.21%
11.4th percentile
A flaw was found in Quay. When an organization acts as a proxy cache, and a user or robot pulls an image that hasn't been mirrored yet, they are granted "Admin" permissions on the newly created repository.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| project_quay | quay | < 3.11.11 | 3.11.11 |
| project_quay | quay | >= 2.14.0 < 3.14.2 | 3.14.2 |
| project_quay | quay | >= 3.12.0 < 3.12.10 | 3.12.10 |
| redhat | quay | <= 3.14.0 | — |
CVSS provenance
nvdv3.16.5MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
vendor_redhat6.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
quay: Incorrect Privilege Assignment
vendor_redhat·2025-05-06·CVSS 6.5
CVE-2025-4374 [MEDIUM] CWE-266 quay: Incorrect Privilege Assignment
quay: Incorrect Privilege Assignment
A flaw was found in Quay. When an organization acts as a proxy cache, and a user or robot pulls an image that hasn't been mirrored yet, they are granted "Admin" permissions on the newly created repository.
A flaw was found in Quay. When an organization acts as a proxy cache, and a user or robot pulls an image that hasn't been mirrored yet, they are granted "Admin" permissions on the newly created repository.
Mitigation: Permissions can be updated after creation but there's no preventative measure before hand.
Package: quay/quay-rhel8 (Red Hat Quay 3) - Affected
GHSA
GHSA-f5vq-pq35-3qqc: A flaw was found in Quay
ghsa_unreviewed·2025-05-06
CVE-2025-4374 [MEDIUM] CWE-266 GHSA-f5vq-pq35-3qqc: A flaw was found in Quay
A flaw was found in Quay. When an organization acts as a proxy cache, and a user or robot pulls an image that hasn't been mirrored yet, they are granted "Admin" permissions on the newly created repository.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2025-05-06
Published