RHBA-2023:6852HighCVSS 7.5

Red Hat Bug Fix Advisory: Red Hat Quay v3.9.5 minor release

Published
November 15, 2023
Last Modified
September 19, 2026

🔗 CVE IDs covered (2)

📋 Description

CVE-2023-39325 — golang: net/http, x/net/http2: rapid stream resets can cause excessive work (CVE-2023-44487) CVE-2023-43804 — python-urllib3: Cookie request header isn't stripped during cross-origin redirects

🎯 Affected products11

  • Quay v3
  • quay/clair-rhel8@sha256:64720f52471e388d2ad55e35380c7e00583b17a9601a031a87cbbe38923793ff_amd64 as a component of Quay v3
  • quay/quay-bridge-operator-bundle@sha256:d264d660840f86395a11593e5860845be7d43caeba46ddbbf0ee959d19d797bd_amd64 as a component of Quay v3
  • quay/quay-bridge-operator-rhel8@sha256:553493a0bce8b643a8329cdc318f75bd50739704c03378ece54ce899787d118c_amd64 as a component of Quay v3
  • quay/quay-builder-qemu-rhcos-rhel8@sha256:c135d032cc5faef785fd6497a18ce507f1e0b25bb1264e7ea5149d7188f0abc5_amd64 as a component of Quay v3
  • quay/quay-builder-rhel8@sha256:08519d06d04385ed9b2128a61baed37b2850e098e7c94d451c036b462d958637_amd64 as a component of Quay v3
  • quay/quay-container-security-operator-bundle@sha256:9ebf9d98530220299f4c70e6af02bbd7b4993ecb2860ba90e8dbf442f3dedcf8_amd64 as a component of Quay v3
  • quay/quay-container-security-operator-rhel8@sha256:b57ba294963ecf71866c646c2dc01a4bac14e2fe7139cb3feee383f361c3fb37_amd64 as a component of Quay v3
  • quay/quay-operator-bundle@sha256:3694b45af16019f667d19f8275d5edc9fcde4809131dd732a89e7f17e5012174_amd64 as a component of Quay v3
  • quay/quay-operator-rhel8@sha256:fbd2d54fe228283f0a8d7ae00982144d0751b89e143a58b2efde0db285496e7d_amd64 as a component of Quay v3
  • quay/quay-rhel8@sha256:3dd323614752b2ac850c6755dcdcdff15c9c660a8b4d7eeee7f5ee3b1eea8352_amd64 as a component of Quay v3

✅ Remediation

Before applying this update, make sure all previously released errata relevant to your system have been applied. For details on how to apply this update, refer to: https://access.redhat.com/articles/11258 Workaround: The default stream concurrency limit in golang is 250 streams (requests) per HTTP/2 connection. This value may be adjusted in the golang.org/x/net/http2 package using the Server.MaxConcurrentStreams setting and the ConfigureServer function which are available in golang.org/x/net/http2. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.

🔗 References (2)