RHSA-2021:0420MediumCVSS 9.8

Red Hat Security Advisory: Red Hat Quay v3.4.0 security update

Published
February 4, 2021
Last Modified
August 15, 2026

🔗 CVE IDs covered (17)

📋 Description

CVE-2019-3866 — openstack-mistral: information disclosure in mistral log CVE-2019-16785 — waitress: HTTP request smuggling through LF vs CRLF handling CVE-2019-16786 — waitress: HTTP request smuggling through invalid Transfer-Encoding CVE-2019-16789 — waitress: HTTP Request Smuggling through Invalid whitespace characters in headers CVE-2019-19911 — python-pillow: uncontrolled resource consumption in FpxImagePlugin.py CVE-2019-20477 — PyYAML: command execution through python/object/apply constructor in FullLoader CVE-2020-5310 — python-pillow: Integer overflow leading to buffer overflow in ImagingLibTiffDecode CVE-2020-5311 — python-pillow: out-of-bounds write in expandrow in libImaging/SgiRleDecode.c CVE-2020-5312 — python-pillow: improperly restricted operations on memory buffer in libImaging/PcxDecode.c CVE-2020-5313 — python-pillow: out-of-bounds read in ImagingFliDecode when loading FLI images CVE-2020-8131 — yarn: Arbitrary filesystem write via tar expansion CVE-2020-10177 — python-pillow: multiple out-of-bounds reads in libImaging/FliDecode.c CVE-2020-10378 — python-pillow: an out-of-bounds read in libImaging/PcxDecode.c can occur when reading PCX files CVE-2020-10379 — python-pillow: two buffer overflows in libImaging/TiffDecode.c due to small buffers allocated in ImagingLibTiffDecode() CVE-2020-10994 — python-pillow: multiple out-of-bounds reads via a crafted JP2 file CVE-2020-11538 — python-pillow: out-of-bounds reads/writes in the parsing of SGI image files in expandrow/expandrow2 CVE-2020-14040 — golang.org/x/text: possibility to trigger an infinite loop in encoding/unicode could lead to crash

🎯 Affected products12

  • Quay v3
  • quay/clair-rhel8@sha256:32d29a9bc9e6f4690d75b432bc36de8555828c7ecabe405f50add88140a13b2d_amd64 as a component of Quay v3
  • quay/quay-bridge-operator-bundle@sha256:cc204e9e439a64232673f7b3c1071ce7d1eee16c0f101688b276aa30eda55b06_amd64 as a component of Quay v3
  • quay/quay-bridge-operator-rhel8@sha256:74af7b3f0fdd7c72395eb4628ded5c38f098bf11bccc5cfba2f4c5698911246c_amd64 as a component of Quay v3
  • quay/quay-builder-qemu-rhcos-rhel8@sha256:324e4fd85bad0dd77f351b1c946040b0be639a63b4f90150e42739efde98a21c_amd64 as a component of Quay v3
  • quay/quay-builder-rhel8@sha256:afc774b0aa286a1a72143ae0ae3491dc6f6005b487bac20c10495c8d98b82165_amd64 as a component of Quay v3
  • quay/quay-container-security-operator-bundle@sha256:70581e0c0ff015d0cb09caeb0e7d76714cd7903df04ae428003c3f8dc3fdb4a3_amd64 as a component of Quay v3
  • quay/quay-container-security-operator-rhel8@sha256:c3642669da261c8a7ee458fcba98abde522bf51e8695c30077840c787abc987e_amd64 as a component of Quay v3
  • quay/quay-openshift-bridge-rhel8-operator@sha256:74af7b3f0fdd7c72395eb4628ded5c38f098bf11bccc5cfba2f4c5698911246c_amd64 as a component of Quay v3
  • quay/quay-operator-bundle@sha256:87a68e36f451d24a493f25a2302897f7009ed7742e405e8e45988837c8b9c7f4_amd64 as a component of Quay v3
  • quay/quay-operator-rhel8@sha256:7bf688be0d6a587c14316c6df81b3a59dba8c308842b67d016bedaedfad95c98_amd64 as a component of Quay v3
  • quay/quay-rhel8@sha256:bdded901debc402b5e5b85bfd3476cc9feda213b846abb2d3ca91d6d91acb34f_amd64 as a component of Quay v3

✅ Remediation

Before applying this update, make sure all previously released errata relevant to your system have been applied. For details on how to apply this update, refer to: https://access.redhat.com/articles/11258 Workaround: Plain text information can be masked by ensuring that all mistral log files are not world readable. Workaround: Use `yaml.safe_load` or the SafeLoader loader when you parse untrusted input.

🔗 References (20)