services / Azure / Container registry quarantined artifacts
Container artifacts (image layers/manifests) held in quarantine pending vulnerability/compliance scanning before being released for general pull; the data action accesses their actual content.
Data-plane access to registry image content, which may include proprietary application code, binaries, and embedded secrets.
Microsoft.ContainerRegistry/registries/quarantinedArtifacts/write
Updates the quarantine state of artifacts, letting an attacker release an unscanned or failed-scan (potentially malicious) image into general availability, bypassing the quarantine security gate.
Risks
Scope: HIGH
This privilege may grant access to sensitive data from a single organizational function, or allow interruption of a service supporting a single organizational function.
Links
Contributed by P0 Security
© 2023–present P0 Security and contributors to the IAM Privilege Catalog