CVE-2025-3528

HIGH

Mirror Registry - Privilege Escalation

Title source: llm
STIX 2.1

Description

A flaw was found in the Mirror Registry. The quay-app container shipped as part of the Mirror Registry for OpenShift has write access to the `/etc/passwd`. This flaw allows a malicious actor with access to the container to modify the passwd file and elevate their privileges to the root user within that pod.

Scores

CVSS v3 8.2
EPSS 0.0004
EPSS Percentile 13.5%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-276
Status published
Products (2)
Red Hat/mirror registry for Red Hat OpenShift
Red Hat/MIRROR-REGISTRY-2.0-RHEL-8 v2.0.7-9
Published May 09, 2025
Tracked Since Feb 18, 2026