CVE-2025-3528 is a high-severity vulnerability affecting the quay-app container within the Mirror Registry for OpenShift, allowing write access to /etc/passwd. An attacker with container access can exploit this flaw to modify the passwd file and elevate privileges to root within the pod. With a CVSS score of 8.2, this local attack requires low complexity but has a high impact on confidentiality, integrity, and availability. There is currently no evidence of active exploitation, public exploit code, or significant community discussion surrounding this vulnerability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
All Versions ImpactedCPE match | cpe:2.3:a:redhat:mirror_registry_for_red_hat_openshift:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.2 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.