RHBA-2023:4275HighCVSS 9.8

Red Hat Bug Fix Advisory: Red Hat Quay v3.8.11 bug fix release

Published
August 10, 2023
Last Modified
August 23, 2026

🔗 CVE IDs covered (14)

📋 Description

CVE-2022-27664 — golang: net/http: handle server errors after sending GOAWAY CVE-2022-32149 — golang: golang.org/x/text/language: ParseAcceptLanguage takes a long time to parse complex tags CVE-2022-32190 — golang: net/url: JoinPath does not strip relative path components in all circumstances CVE-2022-41717 — golang: net/http: excessive memory growth in a Go server accepting HTTP/2 requests CVE-2022-41723 — golang.org/x/net/http2: avoid quadratic complexity in HPACK decoding CVE-2022-41724 — golang: crypto/tls: large handshake records may cause panics CVE-2022-41725 — golang: net/http, mime/multipart: denial of service from excessive resource consumption CVE-2023-24534 — golang: net/http, net/textproto: denial of service from excessive memory allocation CVE-2023-24536 — golang: net/http, net/textproto, mime/multipart: denial of service from excessive resource consumption CVE-2023-24537 — golang: go/parser: Infinite loop in parsing CVE-2023-24538 — golang: html/template: backticks not treated as string delimiters CVE-2023-24539 — golang: html/template: improper sanitization of CSS values CVE-2023-24540 — golang: html/template: improper handling of JavaScript whitespace CVE-2023-29400 — golang: html/template: improper handling of empty HTML attributes

🎯 Affected products11

  • Quay v3
  • quay/clair-rhel8@sha256:dcbe91b758a2db9eeb19cf34ca2c3b2f48f4e61a2f312ac13337f6cfcc2ba7c5_amd64 as a component of Quay v3
  • quay/quay-bridge-operator-bundle@sha256:fde9d641d26bd97ad63b545af91a6f86e67fb252a1d9328c99b026e1a62b3c15_amd64 as a component of Quay v3
  • quay/quay-bridge-operator-rhel8@sha256:1f6f955e901ca25715cdcfcb567bfabf279b4c44f0593120967c4c347806f2d1_amd64 as a component of Quay v3
  • quay/quay-builder-qemu-rhcos-rhel8@sha256:8a3d0913a6b1f323f000435a85fbde56a0021051a2f57e784a17781b677a6d6c_amd64 as a component of Quay v3
  • quay/quay-builder-rhel8@sha256:52d74364ad13706a09cc74e89da5610c452c54b16ebf657a8f435886c76bc697_amd64 as a component of Quay v3
  • quay/quay-container-security-operator-bundle@sha256:69a28778d3dc2af9dcc2ceeeb917eaa38b0736c71f32d781f8bf7e6828852287_amd64 as a component of Quay v3
  • quay/quay-container-security-operator-rhel8@sha256:af56af6433f7cebc28e3c4266c97faf99828e6716cbfad3f5d5883197e0375cd_amd64 as a component of Quay v3
  • quay/quay-operator-bundle@sha256:a97a63899d23e23d039ea36bd575c018d7b6295b7942b15a8bded52f09736bda_amd64 as a component of Quay v3
  • quay/quay-operator-rhel8@sha256:3db71686dc001996d28d3a1ac41b918394806e5b25f6f429705958b6042e63fd_amd64 as a component of Quay v3
  • quay/quay-rhel8@sha256:1abf35ee92122d3811252ce4d31dbc17192758c42434a970cb2d374630abb0cd_amd64 as a component of Quay v3

✅ Remediation

Before applying this update, make sure all previously released errata relevant to your system have been applied. For details on how to apply this update, refer to: https://access.redhat.com/articles/11258 Workaround: Mitigation for this issue is either not available or the currently available options don't meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability. Workaround: To mitigate this issue, upgrade Go to version 1.19.8, 1.20.3, or later, where the vulnerability has been addressed. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.

🔗 References (4)