Where
-Infinity
0
Severity
1

A vulnerability in Quay version 3.8.14 allows successful authentication even when a truncated version of the password is provided. This flaw affects the authentication mechanism, reducing the overall security of password enforcement.

First published (updated )
Severity
8.8
EPSS
0.04%
CSRF
AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

A flaw was found when using mirror-registry to install Quay. It uses a default secret, which is stored in plain-text format in one of the configuration template files. This issue may lead to all instances of Quay deployed using mirror-registry to have the same secret key. This flaw allows a malicious actor to craft session cookies and as a consequence, it may lead to gaining access to the affected Quay instance.

1 / 2
Source: NVD
First published (updated )
Severity
7

An update is now available for Red Hat Quay 3.Security Fix(es): python-werkzeug: high resource usage when parsing multipart form data with many fields (CVE-2023-25577) flask: Possible disclosure of permanent session cookie due to missing Vary: Cookie header (CVE-2023-30861) python-cryptography: memory corruption via immutable objects (CVE-2023-23931) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

1 / 2
Source: Red Hat

Remedy

For details on how to apply this update, which includes the changes described in this advisory, refer to:<br><a href="https://access.redhat.com/articles/11258" target="_blank">https://access.redhat.com/articles/11258</a>
First published (updated )
Severity
4
XSS

The vulnerability exists in the bootbox component of the container image labels within Quay. Specifically, the bootbox title dialog is not properly sanitized.

While the image labels created through Quay undergo validation both in the UI and backend by applying a regex (validation.py), the same validation is not performed when the label comes from an image. This flaw allows an attacker to publish a malicious image to a public registry, containing a script that can be executed via XSS.

First published (updated )

This release of Quay 3.5.7 includes:Security Fix(es): quay/claircore: directory traversal when scanning crafted container image layer allows for arbitrary file write (CVE-2021-3762) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Remedy

For details on how to apply this update, which includes the changes described in this advisory, refer to:<br><a href="https://access.redhat.com/articles/11258" target="_blank">https://access.redhat.com/articles/11258</a>
First published (updated )
Buffer Overflow, Integer Overflow

Quay 3.4.0 release<br>Security Fix(es):<br><li> waitress: HTTP request smuggling through LF vs CRLF handling (CVE-2019-16785)</li> <li> waitress: HTTP request smuggling through invalid Transfer-Encoding (CVE-2019-16786)</li> <li> waitress: HTTP Request Smuggling through Invalid whitespace characters in headers (CVE-2019-16789)</li> <li> python-pillow: Integer overflow leading to buffer overflow in ImagingLibTiffDecode (CVE-2020-5310)</li> <li> python-pillow: out-of-bounds write in expandrow in libImaging/SgiRleDecode.c (CVE-2020-5311)</li> <li> python-pillow: improperly restricted operations on memory buffer in libImaging/PcxDecode.c (CVE-2020-5312)</li> <li> python-pillow: two buffer overflows in libImaging/TiffDecode.c due to small buffers allocated in ImagingLibTiffDecode() (CVE-2020-10379)</li> <li> python-pillow: out-of-bounds reads/writes in the parsing of SGI image files in expandrow/expandrow2 (CVE-2020-11538)</li> <li> openstack-mistral: information disclosure in mistral log (CVE-2019-3866)</li> <li> python-pillow: uncontrolled resource consumption in FpxImagePlugin.py (CVE-2019-19911)</li> <li> PyYAML: command execution through python/object/apply constructor in FullLoader (CVE-2019-20477)</li> <li> python-pillow: out-of-bounds read in ImagingFliDecode when loading FLI images (CVE-2020-5313)</li> <li> yarn: Arbitrary filesystem write via tar expansion (CVE-2020-8131)</li> <li> golang.org/x/text: possibility to trigger an infinite loop in encoding/unicode could lead to crash (CVE-2020-14040)</li> <li> python-pillow: multiple out-of-bounds reads in libImaging/FliDecode.c (CVE-2020-10177)</li> <li> python-pillow: an out-of-bounds read in libImaging/PcxDecode.c can occur when reading PCX files (CVE-2020-10378)</li> <li> python-pillow: multiple out-of-bounds reads via a crafted JP2 file (CVE-2020-10994)</li> For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Remedy

Before applying this update, make sure all previously released errata<br>relevant to your system have been applied.<br>For details on how to apply this update, refer to:<br><a href="https://access.redhat.com/articles/11258" target="_blank">https://access.redhat.com/articles/11258</a>
First published (updated )
XSS

This release of Red Hat Quay v3.3.3 includes:Security Update(s): quay: persistent XSS in repository notification display (CVE-2020-27832) quay: email notifications authorization bypass (CVE-2020-27831) For more details about the security issue(s), including the impact, a CVSSscore, acknowledgments, and other related information, refer to the CVEpage(s) listed in the References section.Bug Fix(es): NVD feed fixed in Clair-v2 (clair-jwt image)

Remedy

Download the release images via:<br>quay.io/redhat/quay:v3.3.3<br>quay.io/redhat/clair-jwt:v3.3.3<br>quay.io/redhat/quay-builder:v3.3.3<br>quay.io/redhat/clair:v3.3.3
First published (updated )

Quay 3.3.1 release, including:Security Fix(es): quay: build triggers can disclose robot account names and existence of private repos within namespaces (CVE-2020-14313) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.Bug Fix(es): Quay 3.3.1 release (BZ#1844197)

Remedy

Please download the release images via:<br>quay.io/redhat/quay:v3.3.1<br>quay.io/redhat/clair-jwt:v3.3.1<br>quay.io/redhat/quay-builder:v3.3.1<br>quay.io/redhat/clair:v3.3.1
First published (updated )

Quay 3.2.1 release, including:Security Fix(es): CVE-2019-10773 nodejs-yarn: Install functionality can be abused to generate arbitrary symlinks For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.Bug Fix(es): Quay 3.2.1 errata (BZ#1793520)

Remedy

Please download the release images via:<br>quay.io/redhat/quay:v3.2.1<br>quay.io/redhat/clair-jwt:v3.2.1<br>quay.io/redhat/quay-builder:v3.2.1
First published (updated )

Quay 3.1.1 errata release, including:<br>Security Fix(es):<br><li> HTTP/2: large amount of data requests leads to denial of service (CVE-2019-9511)</li> <li> HTTP/2: flood using PING frames results in unbounded memory growth (CVE-2019-9512)</li> <li> HTTP/2: flood using PRIORITY frames resulting in excessive resource consumption (CVE-2019-9513)</li> <li> HTTP/2: flood using HEADERS frames results in unbounded memory growth (CVE-2019-9514)</li> <li> HTTP/2: 0-length headers lead to denial of service (CVE-2019-9516)</li> For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.<br>Bug Fix(es):<br><li> Fixed repository mirror credentials properly escaped to allow special characters</li> <li> Fixed repository mirror UI cancel button enabled</li> <li> Fixed repository mirror UI change next sync date</li>

Remedy

Please download the release images via:<br>quay.io/redhat/quay:v3.1.1<br>quay.io/redhat/clair-jwt:v3.1.1<br>quay.io/redhat/quay-builder:v3.1.1
First published (updated )

Security Fix(es):<br><li> A flaw was found in the way the DES/3DES cipher was used as part of the</li> TLS/SSL protocol. A man-in-the-middle attacker could use this flaw to recover some plaintext data by capturing large amounts of encrypted traffic between TLS/SSL server and client if the communication used a DES/3DES based ciphersuite. (CVE-2016-2183)<br>Bug Fix(es):<br><li> Running Quay in config mode now works in a disconnected option which doesn't require pulling resources from the Internet.</li> <li> Quay's security scan endpoint is now enabled at startup for viewing results of Clair container image scans.</li>

Remedy

Before applying this update, make sure all previously released errata<br>relevant to your system have been applied.<br>For details on how to apply this update, refer to:<br><a href="https://access.redhat.com/articles/11258" target="_blank">https://access.redhat.com/articles/11258</a>
First published (updated )

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203