RHSA-2023:7341HighCVSS 7.5
Red Hat Security Advisory: Red Hat Quay security update
🔗 CVE IDs covered (3)
📋 Description
CVE-2023-23931 — python-cryptography: memory corruption via immutable objects CVE-2023-25577 — python-werkzeug: high resource usage when parsing multipart form data with many fields CVE-2023-30861 — flask: Possible disclosure of permanent session cookie due to missing Vary: Cookie header
🎯 Affected products25
- Quay v3
- quay/clair-rhel8@sha256:23859613178852c50bf22697faab3234b14b18a16ebbc7abe2f138a0ce70de7e_amd64 as a component of Quay v3
- quay/clair-rhel8@sha256:88dc472af7cd89ee0bcaf250b3c535a8fab4e92b4faa793efd6d34b13f3d3e1c_s390x as a component of Quay v3
- quay/clair-rhel8@sha256:fa100f2c4a8cab77e72c8747f1a846cd6046afeed0b7c1a580fe2b0d4f1174f5_ppc64le as a component of Quay v3
- quay/quay-builder-qemu-rhcos-rhel8@sha256:23b867fd6a3b732dad7ce74b62fbeacb468e28673600fce321454600c0eb614a_ppc64le as a component of Quay v3
- quay/quay-builder-qemu-rhcos-rhel8@sha256:a908b368daacd5994ba191b7b7a3057f72468e1ea4aee06e1f2d977102499232_amd64 as a component of Quay v3
- quay/quay-builder-qemu-rhcos-rhel8@sha256:eda9b6bb1d237e88481223cb59c4c0b33934782532987242abd04f52f1b8c342_s390x as a component of Quay v3
- quay/quay-builder-rhel8@sha256:47bb83c9964c153c965c09bce04e4a5a4b59e6d6a7f141164ab8c5ab0e410205_ppc64le as a component of Quay v3
- quay/quay-builder-rhel8@sha256:579e02e548e7add12043a000a68b68e290871fd6f9f850b9c8da655005545db5_s390x as a component of Quay v3
- quay/quay-builder-rhel8@sha256:747705d85d04b80cb01fd4dc293dae29a4547c6c52edf78366c4abe9e2dc40bf_amd64 as a component of Quay v3
- quay/quay-container-security-operator-bundle@sha256:3ce921816cc1dc34009a1f44f651756f25fdbe55f03751f73bc28e820a76a3e4_s390x as a component of Quay v3
- quay/quay-container-security-operator-bundle@sha256:a7c62a3852c6fe8a83e187af9a9d8378731c17162996d2fd9d4964d5057c00ae_amd64 as a component of Quay v3
- quay/quay-container-security-operator-bundle@sha256:d083fc73b5aaa20105369053a4f247d90f6bf963ba4216a4a115d36d62eb87ca_ppc64le as a component of Quay v3
- quay/quay-container-security-operator-rhel8@sha256:099a934e8dcb0161e0e4060f2898c963a90cc0738442e99fae083b0f30bc142e_amd64 as a component of Quay v3
- quay/quay-container-security-operator-rhel8@sha256:655de4673f8b018cc323a74988e71f5680ff330243f600f74d6a562b129e188f_s390x as a component of Quay v3
- quay/quay-container-security-operator-rhel8@sha256:6a18fdba3c2bc93ff6e511e3b2fce591b8a186eb1d32639e825df25478e5c9a9_ppc64le as a component of Quay v3
- quay/quay-operator-bundle@sha256:0e0b3af9b4b673ea2b1f0276caf82fb51c8b6fa9c15874c79028d18a3344bd4c_amd64 as a component of Quay v3
- quay/quay-operator-bundle@sha256:3776ee296f1c7d89d600016199d29248aac978729a88007af0870612692ff3e6_s390x as a component of Quay v3
- quay/quay-operator-bundle@sha256:baa04276b08ffe601f7ca30ff68b81713a2ee6385295d577ba56140813996b5d_ppc64le as a component of Quay v3
- quay/quay-operator-rhel8@sha256:0a85707172eab0ee157e6df85844f1950af36c2c8b755ac97fd5802184ba5eed_ppc64le as a component of Quay v3
- quay/quay-operator-rhel8@sha256:4f44290cc1469dd106bb0728e4af614dcb0ba3f429be9f6dc2e580c9378bd108_s390x as a component of Quay v3
- quay/quay-operator-rhel8@sha256:e6e09ebcccfb8f8a0c6744738a62ba257536344d2a8752a74848d30ab68cfd56_amd64 as a component of Quay v3
- quay/quay-rhel8@sha256:48760e344a72b56fa1b747af7935ac9ec94f63329a8fb6369093b7283156657c_amd64 as a component of Quay v3
- quay/quay-rhel8@sha256:4f9f10b08ce70ec734a3a422082353498c42768469fcab73e2fc948e38a1ee90_s390x as a component of Quay v3
- quay/quay-rhel8@sha256:de2671e861ebe80195be0c7d1031ec88106329d9e6d061a88a35a8430277ea7a_ppc64le as a component of Quay v3
✅ Remediation
For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258
🔗 References (23)
- selfhttps://access.redhat.com/errata/RHSA-2023:7341
- externalhttps://access.redhat.com/security/updates/classification/#important
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2170242
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2171817
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2196643
- externalhttps://issues.redhat.com/browse/PROJQUAY-2462
- externalhttps://issues.redhat.com/browse/PROJQUAY-2803
- externalhttps://issues.redhat.com/browse/PROJQUAY-3906
- externalhttps://issues.redhat.com/browse/PROJQUAY-4126
- externalhttps://issues.redhat.com/browse/PROJQUAY-5021
- externalhttps://issues.redhat.com/browse/PROJQUAY-5212
- externalhttps://issues.redhat.com/browse/PROJQUAY-5489
- externalhttps://issues.redhat.com/browse/PROJQUAY-5506
- externalhttps://issues.redhat.com/browse/PROJQUAY-5598
- externalhttps://issues.redhat.com/browse/PROJQUAY-5957
- externalhttps://issues.redhat.com/browse/PROJQUAY-5958
- externalhttps://issues.redhat.com/browse/PROJQUAY-5959
- externalhttps://issues.redhat.com/browse/PROJQUAY-5960
- externalhttps://issues.redhat.com/browse/PROJQUAY-5963
- externalhttps://issues.redhat.com/browse/PROJQUAY-6010
- externalhttps://issues.redhat.com/browse/PROJQUAY-6048
- externalhttps://issues.redhat.com/browse/PROJQUAY-6184
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2023/rhsa-2023_7341.json