A flaw was found in Quay. When an organization acts as a proxy cache, and a user or robot pulls an image that hasn't been mirrored yet, they are granted "Admin" permissions on the newly created repository.
Advisories
Source ID Title
EUVD EUVD EUVD-2025-13599 A flaw was found in Quay. When an organization acts as a proxy cache, and a user or robot pulls an image that hasn't been mirrored yet, they are granted "Admin" permissions on the newly created repository.
Fixes

Solution

No solution given by the vendor.


Workaround

Permissions can be updated after creation but there's no preventative measure before hand.

History

Thu, 31 Jul 2025 18:15:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:redhat:quay:*:*:*:*:*:*:*:*

Sun, 13 Jul 2025 13:45:00 +0000

Type Values Removed Values Added
Metrics epss

{'score': 0.00039}

epss

{'score': 0.00041}


Tue, 06 May 2025 20:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 06 May 2025 15:00:00 +0000

Type Values Removed Values Added
Description No description is available for this CVE. A flaw was found in Quay. When an organization acts as a proxy cache, and a user or robot pulls an image that hasn't been mirrored yet, they are granted "Admin" permissions on the newly created repository.
Title quay: Incorrect Privilege Assignment Quay: incorrect privilege assignment
First Time appeared Redhat
Redhat quay
CPEs cpe:/a:redhat:quay:3
Vendors & Products Redhat
Redhat quay
References

Tue, 06 May 2025 14:30:00 +0000

Type Values Removed Values Added
Description No description is available for this CVE.
Title quay: Incorrect Privilege Assignment
Weaknesses CWE-266
References
Metrics threat_severity

None

cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N'}

threat_severity

Moderate


cve-icon MITRE

Status: PUBLISHED

Assigner: redhat

Published:

Updated: 2025-09-25T02:45:39.346Z

Reserved: 2025-05-06T01:24:21.315Z

Link: CVE-2025-4374

cve-icon Vulnrichment

Updated: 2025-05-06T19:50:17.750Z

cve-icon NVD

Status : Analyzed

Published: 2025-05-06T15:16:05.463

Modified: 2025-07-31T18:00:55.420

Link: CVE-2025-4374

cve-icon Redhat

Severity : Moderate

Publid Date: 2025-05-06T00:00:00Z

Links: CVE-2025-4374 - Bugzilla

cve-icon OpenCVE Enrichment

No data.