CVE-2025-58712 identifies a container privilege escalation vulnerability in certain AMQ Broker images, stemming from the /etc/passwd file being group-writable during build time. This flaw allows an attacker, who can execute commands as a non-root user within the root group, to modify the /etc/passwd file and gain full root privileges inside the container. Rated as Medium severity (CVSS 6.4), exploitation requires high privileges and high attack complexity, but can lead to complete compromise of the container. There is currently no evidence of active exploitation, public exploit code, or significant community discussion regarding this vulnerability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| Red Hat | Red Hat AMQ Broker 7 | All Versions ImpactedCNA affecteddefault affected | |
| Red Hat | RHEL-9 Based Middleware Containers | Range not provided by sourceCNA affecteddefault affected |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.