GHSA-f5vq-pq35-3qqcMediumCVSS 6.5

A flaw was found in Quay. When an organization acts as a proxy cache, and a user or robot pulls...

Published
May 6, 2025
Last Modified
August 7, 2026

🔗 CVE IDs covered (1)

📋 Description

A flaw was found in Quay. When an organization acts as a proxy cache, and a user or robot pulls an image that hasn't been mirrored yet, they are granted "Admin" permissions on the newly created repository.

🔗 References (8)