« Back to list

CVE-2025-3528

Status: DeferredHigh (8.2)—

A flaw was found in the Mirror Registry. The quay-app container shipped as part of the Mirror Registry for OpenShift has write access to the `/etc/passwd`. This flaw allows a malicious actor with access to the container to modify the passwd file and elevate their privileges to the root user within that pod.

CVSS

Exploitation probability (EPSS)

EPSS (Exploit Prediction Scoring System, FIRST) estimates how likely a vulnerability is to be exploited in the wild within 30 days. It complements CVSS (impact) and CISA KEV (confirmed exploitation).

🎯 ATT&CK techniques

How this vulnerability is exploited and what the attacker gains, in MITRE ATT&CK terms.

UI:R + acceso local (AV:L) indican ejecución en cliente. La descripción explícita de escalada a root (T1068) y modificación de passwd (T1222) son los impactos primarios.

Inferred by our analysis agent from the official description, CVSS vector and CWE, and checked by a supervisor. May contain errors.

🛡️ ATT&CK mitigations that cover these techniques

Affected technologies (2)

⚠ AI-inferred from the description — NVD hasn't analyzed this CVE yet, these aren't verified CPEs.

CWEs

References

Raw JSON (NVD)

Show
{
  "id": "CVE-2025-3528",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2025-3528",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "none"
            },
            {
              "automatable": "no"
            },
            {
              "technicalImpact": "total"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2025-05-09T14:01:56.315475Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "secalert@redhat.com",
        "cvssData": {
          "scope": "CHANGED",
          "version": "3.1",
          "baseScore": 8.2,
          "attackVector": "LOCAL",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H",
          "integrityImpact": "HIGH",
          "userInteraction": "REQUIRED",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 6,
        "exploitabilityScore": 1.5
      }
    ]
  },
  "affected": [
    {
      "source": "secalert@redhat.com",
      "affectedData": [
        {
          "versions": [
            {
              "status": "affected",
              "version": "0",
              "lessThan": "2",
              "versionType": "custom"
            }
          ],
          "packageName": "mirror-registry",
          "collectionURL": "https://access.redhat.com/downloads/content/686/ver=2/rhel---8/2/x86_64/product-software",
          "defaultStatus": "unaffected"
        },
        {
          "cpes": [
            "cpe:/a:redhat:mirror_registry:2.0.0::el8"
          ],
          "vendor": "Red Hat",
          "product": "MIRROR-REGISTRY-2.0-RHEL-8",
          "versions": [
            {
              "status": "unaffected",
              "version": "v2.0.7-9",
              "lessThan": "*",
              "versionType": "rpm"
            }
          ],
          "packageName": "openshift/mirror-registry-rhel8",
          "collectionURL": "https://catalog.redhat.com/software/containers/",
          "defaultStatus": "affected"
        },
        {
          "cpes": [
            "cpe:/a:redhat:mirror_registry:1"
          ],
          "vendor": "Red Hat",
          "product": "mirror registry for Red Hat OpenShift",
          "packageName": "mirror-registry-container",
          "collectionURL": "https://catalog.redhat.com/software/containers/",
          "defaultStatus": "affected"
        }
      ]
    }
  ],
  "published": "2025-05-09T12:15:33.223",
  "references": [
    {
      "url": "https://access.redhat.com/errata/RHBA-2025:9645",
      "source": "secalert@redhat.com"
    },
    {
      "url": "https://access.redhat.com/security/cve/CVE-2025-3528",
      "source": "secalert@redhat.com"
    },
    {
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2359143",
      "source": "secalert@redhat.com"
    }
  ],
  "vulnStatus": "Deferred",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "secalert@redhat.com",
      "description": [
        {
          "lang": "en",
          "value": "CWE-276"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "A flaw was found in the Mirror Registry. The quay-app container shipped as part of the Mirror Registry for OpenShift has write access to the `/etc/passwd`. This flaw allows a malicious actor with access to the container to modify the passwd file and elevate their privileges to the root user within that pod."
    },
    {
      "lang": "es",
      "value": "Se detectó una falla en Mirror Registry. El contenedor quay-app, incluido en el Registro Mirror para OpenShift, tiene acceso de escritura al archivo `/etc/passwd`. Esta falla permite que un usuario malicioso con acceso al contenedor modifique el archivo passwd y ascienda sus privilegios al usuario root dentro de ese pod."
    }
  ],
  "lastModified": "2026-06-17T09:20:06.973",
  "sourceIdentifier": "secalert@redhat.com"
}