RHSA-2023:7341: Important: Red Hat Quay security update
An update is now available for Red Hat Quay 3.Security Fix(es): python-werkzeug: high resource usage when parsing multipart form data with many fields (CVE-2023-25577) flask: Possible disclosure of permanent session cookie due to missing Vary: Cookie header (CVE-2023-30861) python-cryptography: memory corruption via immutable objects (CVE-2023-23931) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of RHSA-2023:7341?
The severity of RHSA-2023:7341 is high.
What is the update about?
The update is an important security update for Red Hat Quay.
Which software is affected by RHSA-2023:7341?
Red Hat Quay, Red Hat Quay for IBM Power, little endian, and Red Hat Quay for IBM Z and LinuxONE are affected.
Where can I find more information about RHSA-2023:7341?
You can find more information about RHSA-2023:7341 on the Red Hat website.
How can I apply the security update?
You can apply the security update by following the instructions provided by Red Hat.