Red Hat Mirror Registry Privilege Escalation Vulnerability

Vulnerability

A privilege escalation vulnerability exists in the quay-app container of the Mirror Registry for OpenShift. The flaw allows a malicious actor with access to the container to modify the passwd file, potentially elevating privileges to the root user within the pod.

Impact

Exploitation of this vulnerability allows for local privilege escalation to the root user within the affected pod.

Remediation

To mitigate this vulnerability, add '--security-opt=no-new-privileges' in each Mirror Registry systemd configuration. This will prevent privilege escalation until the issue is resolved.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
2.5
exploitability
3.3
remediation
0.0
relevance
0.0
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.