RHSA-2020:0475: Important: Red Hat Quay v3.2.1 security update
Quay 3.2.1 release, including:Security Fix(es): CVE-2019-10773 nodejs-yarn: Install functionality can be abused to generate arbitrary symlinks For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.Bug Fix(es): Quay 3.2.1 errata (BZ#1793520)
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of RHSA-2020:0475?
The severity of RHSA-2020:0475 is classified as important.
How do I fix RHSA-2020:0475?
To fix RHSA-2020:0475, update the Red Hat Quay software to the latest version that addresses the vulnerabilities.
What vulnerabilities are addressed in RHSA-2020:0475?
RHSA-2020:0475 addresses the CVE-2019-10773 vulnerability in nodejs-yarn related to symlink creation.
What software is affected by RHSA-2020:0475?
The affected software for RHSA-2020:0475 is Red Hat Quay.
What impact does CVE-2019-10773 have as noted in RHSA-2020:0475?
CVE-2019-10773 allows an attacker to exploit the install functionality to create arbitrary symlinks, potentially leading to security breaches.