CVE-2025-3528: Red Hat Mirror-Registry-2.0-Rhel-8

High severity, CVSS 8.2. EPSS: 0.2% chance of exploitation in the next 30 days.

A flaw was found in the Mirror Registry. The quay-app container shipped as part of the Mirror Registry for OpenShift has write access to the `/etc/passwd`. This flaw allows a malicious actor with access to the container to modify the passwd file and elevate their privileges to the root user within that pod.

Affected products

  • Red Hat Mirror-Registry-2.0-Rhel-8: before v2.0.7-9 (fixed in v2.0.7-9)
  • Red Hat Mirror Registry For Red Hat Openshift

Published 2025-05-09. Last modified 2026-06-17.