First published: Thu Oct 03 2019(Updated: )
Quay 3.1.1 errata release, including:<br>Security Fix(es):<br><li> HTTP/2: large amount of data requests leads to denial of service (CVE-2019-9511)</li> <li> HTTP/2: flood using PING frames results in unbounded memory growth (CVE-2019-9512)</li> <li> HTTP/2: flood using PRIORITY frames resulting in excessive resource consumption (CVE-2019-9513)</li> <li> HTTP/2: flood using HEADERS frames results in unbounded memory growth (CVE-2019-9514)</li> <li> HTTP/2: 0-length headers lead to denial of service (CVE-2019-9516)</li> For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.<br>Bug Fix(es):<br><li> Fixed repository mirror credentials properly escaped to allow special characters</li> <li> Fixed repository mirror UI cancel button enabled</li> <li> Fixed repository mirror UI change next sync date</li>
Affected Software | Affected Version | How to fix |
---|
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.