CVE-2025-4374: Red Hat Quay
Medium severity, CVSS 6.5. EPSS: 0.3% chance of exploitation in the next 30 days.
A flaw was found in Quay. When an organization acts as a proxy cache, and a user or robot pulls an image that hasn't been mirrored yet, they are granted "Admin" permissions on the newly created repository.
Affected products
- Red Hat Quay: up to and including 3.14.0
Published 2025-05-06. Last modified 2026-08-07.