Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.
Reconnecting to live updates…

CVE-2025-3528: Incorrect Default Permissions

0
High
VulnerabilityCVE-2025-3528cvecve-2025-3528
Published: Fri May 09 2025 (05/09/2025, 11:58:24 UTC)
Source: CVE
Vendor/Project: Red Hat
Product: mirror registry for Red Hat OpenShift

Description

A flaw was found in the Mirror Registry. The quay-app container shipped as part of the Mirror Registry for OpenShift has write access to the `/etc/passwd`. This flaw allows a malicious actor with access to the container to modify the passwd file and elevate their privileges to the root user within that pod.

AI-Powered Analysis

AILast updated: 11/20/2025, 07:53:46 UTC

Technical Analysis

CVE-2025-3528 identifies a critical security flaw in the Mirror Registry component of Red Hat OpenShift, specifically within the quay-app container. The vulnerability arises because the quay-app container is shipped with write permissions to the /etc/passwd file, a critical system file that controls user account information. This incorrect default permission setting allows any user or process with access to the container to modify the passwd file, enabling privilege escalation to root within the pod. The flaw is significant because gaining root privileges inside a container can allow an attacker to manipulate the container environment, potentially leading to further lateral movement or disruption within the cluster. The CVSS score of 8.2 reflects the high impact on confidentiality, integrity, and availability, with an attack vector limited to local access (AV:L), low attack complexity (AC:L), requiring low privileges (PR:L) and user interaction (UI:R). The scope is changed (S:C), meaning the vulnerability affects resources beyond the initially compromised component. Although no known exploits are currently reported in the wild, the vulnerability's nature makes it a critical risk for environments that deploy the Mirror Registry without additional hardening. The flaw affects all versions of the Mirror Registry as indicated by the affectedVersions field. The vulnerability was published on May 9, 2025, and is tracked under CVE-2025-3528. The Mirror Registry is a key component in OpenShift for managing container images, making this vulnerability particularly impactful in Kubernetes/OpenShift environments.

Potential Impact

For European organizations, the impact of CVE-2025-3528 can be severe, especially for those relying on Red Hat OpenShift for container orchestration and deployment. Successful exploitation allows attackers to escalate privileges to root within the container pod, potentially leading to unauthorized access to sensitive data, disruption of services, or further compromise of the cluster. This can undermine the confidentiality and integrity of workloads running in OpenShift, impacting business-critical applications. Given the widespread adoption of OpenShift in sectors such as finance, telecommunications, and government across Europe, the vulnerability poses a significant risk to operational continuity and data protection compliance. Additionally, the ability to alter the /etc/passwd file could facilitate persistence mechanisms or lateral movement within the cluster, increasing the attack surface. The requirement for local access and user interaction somewhat limits remote exploitation but does not eliminate risk, especially in multi-tenant or shared environments where container access might be easier to obtain.

Mitigation Recommendations

To mitigate CVE-2025-3528, organizations should immediately review and restrict permissions granted to the quay-app container within the Mirror Registry. Specifically, ensure that the container does not have write access to critical system files such as /etc/passwd. Applying the latest patches or updates from Red Hat as they become available is essential. In the absence of patches, implement container security best practices including: running containers with the least privilege principle, using read-only file systems where possible, and employing security contexts and Pod Security Policies to restrict container capabilities. Additionally, enable and monitor audit logs for container access and changes to sensitive files. Network segmentation and strict access controls should be enforced to limit who can interact with the Mirror Registry containers. Employ runtime security tools to detect anomalous behavior indicative of privilege escalation attempts. Regularly scan container images for misconfigurations and vulnerabilities before deployment. Finally, educate DevOps and security teams about this vulnerability to ensure rapid detection and response.

Need more detailed analysis?Upgrade to Pro Console

Technical Details

Data Version
5.1
Assigner Short Name
redhat
Date Reserved
2025-04-11T18:46:42.874Z
Cisa Enriched
true
Cvss Version
3.1
State
PUBLISHED

Threat ID: 682d9818c4522896dcbd7a5c

Added to database: 5/21/2025, 9:08:40 AM

Last enriched: 11/20/2025, 7:53:46 AM

Last updated: 1/7/2026, 4:21:12 AM

Views: 49

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console in Console -> Billing for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats