A vulnerability in Quay version 3.8.14 allows successful authentication even when a truncated version of the password is provided. This flaw affects the authentication mechanism, reducing the overall security of password enforcement.
A flaw was found when using mirror-registry to install Quay. It uses a default secret, which is stored in plain-text format in one of the configuration template files. This issue may lead to all instances of Quay deployed using mirror-registry to have the same secret key. This flaw allows a malicious actor to craft session cookies and as a consequence, it may lead to gaining access to the affected Quay instance.
An update is now available for Red Hat Quay 3.Security Fix(es): python-werkzeug: high resource usage when parsing multipart form data with many fields (CVE-2023-25577) flask: Possible disclosure of permanent session cookie due to missing Vary: Cookie header (CVE-2023-30861) python-cryptography: memory corruption via immutable objects (CVE-2023-23931) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
The vulnerability exists in the bootbox component of the container image labels within Quay. Specifically, the bootbox title dialog is not properly sanitized.
While the image labels created through Quay undergo validation both in the UI and backend by applying a regex (validation.py), the same validation is not performed when the label comes from an image. This flaw allows an attacker to publish a malicious image to a public registry, containing a script that can be executed via XSS.
This release of Quay 3.5.7 includes:Security Fix(es): quay/claircore: directory traversal when scanning crafted container image layer allows for arbitrary file write (CVE-2021-3762) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Quay 3.4.0 release<br>Security Fix(es):<br><li> waitress: HTTP request smuggling through LF vs CRLF handling (CVE-2019-16785)</li> <li> waitress: HTTP request smuggling through invalid Transfer-Encoding (CVE-2019-16786)</li> <li> waitress: HTTP Request Smuggling through Invalid whitespace characters in headers (CVE-2019-16789)</li> <li> python-pillow: Integer overflow leading to buffer overflow in ImagingLibTiffDecode (CVE-2020-5310)</li> <li> python-pillow: out-of-bounds write in expandrow in libImaging/SgiRleDecode.c (CVE-2020-5311)</li> <li> python-pillow: improperly restricted operations on memory buffer in libImaging/PcxDecode.c (CVE-2020-5312)</li> <li> python-pillow: two buffer overflows in libImaging/TiffDecode.c due to small buffers allocated in ImagingLibTiffDecode() (CVE-2020-10379)</li> <li> python-pillow: out-of-bounds reads/writes in the parsing of SGI image files in expandrow/expandrow2 (CVE-2020-11538)</li> <li> openstack-mistral: information disclosure in mistral log (CVE-2019-3866)</li> <li> python-pillow: uncontrolled resource consumption in FpxImagePlugin.py (CVE-2019-19911)</li> <li> PyYAML: command execution through python/object/apply constructor in FullLoader (CVE-2019-20477)</li> <li> python-pillow: out-of-bounds read in ImagingFliDecode when loading FLI images (CVE-2020-5313)</li> <li> yarn: Arbitrary filesystem write via tar expansion (CVE-2020-8131)</li> <li> golang.org/x/text: possibility to trigger an infinite loop in encoding/unicode could lead to crash (CVE-2020-14040)</li> <li> python-pillow: multiple out-of-bounds reads in libImaging/FliDecode.c (CVE-2020-10177)</li> <li> python-pillow: an out-of-bounds read in libImaging/PcxDecode.c can occur when reading PCX files (CVE-2020-10378)</li> <li> python-pillow: multiple out-of-bounds reads via a crafted JP2 file (CVE-2020-10994)</li> For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
This release of Red Hat Quay v3.3.3 includes:Security Update(s): quay: persistent XSS in repository notification display (CVE-2020-27832) quay: email notifications authorization bypass (CVE-2020-27831) For more details about the security issue(s), including the impact, a CVSSscore, acknowledgments, and other related information, refer to the CVEpage(s) listed in the References section.Bug Fix(es): NVD feed fixed in Clair-v2 (clair-jwt image)
Quay 3.3.1 release, including:Security Fix(es): quay: build triggers can disclose robot account names and existence of private repos within namespaces (CVE-2020-14313) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.Bug Fix(es): Quay 3.3.1 release (BZ#1844197)
Quay 3.2.1 release, including:Security Fix(es): CVE-2019-10773 nodejs-yarn: Install functionality can be abused to generate arbitrary symlinks For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.Bug Fix(es): Quay 3.2.1 errata (BZ#1793520)
Quay 3.1.1 errata release, including:<br>Security Fix(es):<br><li> HTTP/2: large amount of data requests leads to denial of service (CVE-2019-9511)</li> <li> HTTP/2: flood using PING frames results in unbounded memory growth (CVE-2019-9512)</li> <li> HTTP/2: flood using PRIORITY frames resulting in excessive resource consumption (CVE-2019-9513)</li> <li> HTTP/2: flood using HEADERS frames results in unbounded memory growth (CVE-2019-9514)</li> <li> HTTP/2: 0-length headers lead to denial of service (CVE-2019-9516)</li> For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.<br>Bug Fix(es):<br><li> Fixed repository mirror credentials properly escaped to allow special characters</li> <li> Fixed repository mirror UI cancel button enabled</li> <li> Fixed repository mirror UI change next sync date</li>
Security Fix(es):<br><li> A flaw was found in the way the DES/3DES cipher was used as part of the</li> TLS/SSL protocol. A man-in-the-middle attacker could use this flaw to recover some plaintext data by capturing large amounts of encrypted traffic between TLS/SSL server and client if the communication used a DES/3DES based ciphersuite. (CVE-2016-2183)<br>Bug Fix(es):<br><li> Running Quay in config mode now works in a disconnected option which doesn't require pulling resources from the Internet.</li> <li> Quay's security scan endpoint is now enabled at startup for viewing results of Clair container image scans.</li>