Uploaded image for project: 'Project Quay'
  1. Project Quay
  2. PROJQUAY-1747

Security Vulnerabilities in Quay 3.4.x using Prima

XMLWordPrintable

    • Icon: Bug Bug
    • Resolution: Won't Do
    • Icon: Major Major
    • None
    • None
    • quay
    • False
    • False
    • Quay Enterprise
    • Undefined
    • 0

      Apart from UI related CVE, We see there are few other CVE like CVE-2020-1747 which is caused due to pyyaml 5.3 version which is used in latest version Quay.

      However the advisory[1] mentions its affected but mentions it will not  fix, any reason for that ?

      Also we have couple of more non UI releated CVE, attaching complete list from Prisma Scanner

       

      [1]https://access.redhat.com/security/cve/cve-2020-1747 

      [2]https://access.redhat.com/security/cve/cve-2020-14343

            Unassigned Unassigned
            rhn-support-dgangaia Dixit Gangaiah (Inactive)
            Votes:
            0 Vote for this issue
            Watchers:
            3 Start watching this issue

              Created:
              Updated:
              Resolved: