CVE-2025-4374

Publication date

2025-05-06 14:49:28

Family

redhat

State

PUBLISHED

Description

A flaw was found in Quay. When an organization acts as a proxy cache, and a user or robot pulls an image that hasnt been mirrored yet, they are granted "Admin" permissions on the newly created repository.