Skip to navigation Skip to main content

Utilities

  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
Red Hat Customer Portal
  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
  • Products

    Top Products

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Products

    Downloads and Containers

    • Downloads
    • Packages
    • Containers

    Top Resources

    • Documentation
    • Product Life Cycles
    • Product Compliance
    • Errata
  • Knowledge

    Red Hat Knowledge Center

    • Knowledgebase Solutions
    • Knowledgebase Articles
    • Customer Portal Labs
    • Errata

    Top Product Docs

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Product Docs

    Training and Certification

    • About
    • Course Index
    • Certification Index
    • Skill Assessment
  • Security

    Red Hat Product Security Center

    • Security Updates
    • Security Advisories
    • Red Hat CVE Database
    • Errata

    References

    • Security Bulletins
    • Security Measurement
    • Severity Ratings
    • Security Data

    Top Resources

    • Security Labs
    • Backporting Policies
    • Security Blog
  • Support

    Red Hat Support

    • Support Cases
    • Troubleshoot
    • Get Support
    • Contact Red Hat Support

    Red Hat Community Support

    • Customer Portal Community
    • Community Discussions
    • Red Hat Accelerator Program

    Top Resources

    • Product Life Cycles
    • Customer Portal Labs
    • Red Hat JBoss Supported Configurations
    • Red Hat Insights
Or troubleshoot an issue.

Select Your Language

  • English
  • Français
  • 한국어
  • 日本語
  • 中文 (中国)

Infrastructure and Management

  • Red Hat Enterprise Linux
  • Red Hat Satellite
  • Red Hat Subscription Management
  • Red Hat Insights
  • Red Hat Ansible Automation Platform

Cloud Computing

  • Red Hat OpenShift
  • Red Hat OpenStack Platform
  • Red Hat OpenShift
  • Red Hat OpenShift AI
  • Red Hat OpenShift Dedicated
  • Red Hat Advanced Cluster Security for Kubernetes
  • Red Hat Advanced Cluster Management for Kubernetes
  • Red Hat Quay
  • Red Hat OpenShift Dev Spaces
  • Red Hat OpenShift Service on AWS

Storage

  • Red Hat Gluster Storage
  • Red Hat Hyperconverged Infrastructure
  • Red Hat Ceph Storage
  • Red Hat OpenShift Data Foundation

Runtimes

  • Red Hat Runtimes
  • Red Hat JBoss Enterprise Application Platform
  • Red Hat Data Grid
  • Red Hat JBoss Web Server
  • Red Hat build of Keycloak
  • Red Hat support for Spring Boot
  • Red Hat build of Node.js
  • Red Hat build of Quarkus

Integration and Automation

  • Red Hat Application Foundations
  • Red Hat Fuse
  • Red Hat AMQ
  • Red Hat 3scale API Management
All Products
Red Hat Product Errata RHBA-2024:9478 - Bug Fix Advisory
Issued:
2024-11-19
Updated:
2024-11-19

RHBA-2024:9478 - Bug Fix Advisory

  • Overview
  • Updated Images

Synopsis

Red Hat Quay v3.13.1 bug fix release

Type/Severity

Bug Fix Advisory

Topic

Red Hat Quay 3.13.1 is now available with bug fixes.

Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section.

Description

Quay 3.13.1

Solution

Before applying this update, make sure all previously released errata relevant to your system have been applied.

For details on how to apply this update, refer to:

https://access.redhat.com/articles/11258

Affected Products

  • Red Hat Quay Enterprise 3 x86_64

Fixes

  • PROJQUAY-5086 - Quay instance is still producing HPA for some operator-unmanaged components.
  • PROJQUAY-8024 - Quay 3.12.3 pull image was failed with 403 error code with Hitachi HCP V9.7
  • PROJQUAY-8185 - Quay operator 3.13 failed to upgrade managed clair postgres on openshift with FIPS enabled
  • PROJQUAY-8229 - [3.13] GLOBAL_READONLY_SUPER_USERS doesn't work for /v2/_catalog endpoint

CVEs

  • CVE-2019-12900
  • CVE-2021-43618
  • CVE-2023-6004
  • CVE-2023-6918
  • CVE-2023-25193
  • CVE-2023-37328
  • CVE-2023-37920
  • CVE-2024-2398
  • CVE-2024-3596
  • CVE-2024-3651
  • CVE-2024-4032
  • CVE-2024-5535
  • CVE-2024-6232
  • CVE-2024-6345
  • CVE-2024-6923
  • CVE-2024-25062
  • CVE-2024-28182
  • CVE-2024-28834
  • CVE-2024-37891
  • CVE-2024-40897
  • CVE-2024-45490
  • CVE-2024-45491
  • CVE-2024-45492
  • CVE-2024-50602

References

(none)

ppc64le

quay/clair-rhel8@sha256:ac22e9317effa4937f161313cf319b5e75d6bb89f49359d74f9777f92bcb50d2
quay/quay-bridge-operator-bundle@sha256:272bcd977f91ec20fd17c85b7427980fcf8f388961fece1e9299f45b382f52a2
quay/quay-bridge-operator-rhel8@sha256:269fff43e7d66775acd942c164c8b18a1dd2b44caad9443514afa969671e4d20
quay/quay-builder-qemu-rhcos-rhel8@sha256:cd43dc5ab4dd726405ec10d4db2f86db589776f0559111d28db2e94ca0784470
quay/quay-builder-rhel8@sha256:625fe2a98f63b3b26e10983e5e25e291260b05e347b2cef2afb4a02ab8963c9f
quay/quay-container-security-operator-bundle@sha256:2e9fffbc94c3e94a8fa298d1f4e9e1e18b665444161a9d79f648d50e816c80a5
quay/quay-container-security-operator-rhel8@sha256:4ef9b8ff4e7a7f1a12e56e52eb6fd22917323198bd5cd965567a1bca5a1ae0c3
quay/quay-operator-bundle@sha256:2d3836cda47319506e0b35c2edce73fdbcc85a550f65e3f781784a276a3c23f2
quay/quay-operator-rhel8@sha256:af0f10baa8e97b7bbad844925d37201069922147f888e6505c6134513566e2a7
quay/quay-rhel8@sha256:81a1f51cbdd8f10a483cebfab2076dcd59f0056e80c9b8defc7f647904db88a7

s390x

quay/clair-rhel8@sha256:f4bae422ffde79511204bb7536f4d3ee88fcb243fd685262b6dcf3e590c48584
quay/quay-bridge-operator-bundle@sha256:369c008de766ebfb2f1260010991a866ce3443af48919720b457212723ec0019
quay/quay-bridge-operator-rhel8@sha256:ef0b533a3a820082ae1e5286bc16ab5ec8a1ce0938dfce0435d01ac8cb9df17d
quay/quay-builder-qemu-rhcos-rhel8@sha256:e687bbc6998cc2042f6f9e8db681a5b018236d7c71329ecf8a79c31a68dad02c
quay/quay-builder-rhel8@sha256:cb350a23cef4e1f69db4da45745dbf7cdb381af798d94be63a0c0f6681db0c9d
quay/quay-container-security-operator-bundle@sha256:ced9fe45962ddf2549292f0e5331eb6669de7dba13d4912224329bbc64035f70
quay/quay-container-security-operator-rhel8@sha256:2e53ec2c633dca19c541c7b467039ab7f57f43ef68e6c4005abc65ce8b05c655
quay/quay-operator-bundle@sha256:adaecc976bc2ff3cd6f6473a1f530109d4268a1709179063542c6ac1c7238a39
quay/quay-operator-rhel8@sha256:56a95ebac1140268f1b195e3b5eabc2a46c949de957ec67d7ef685e9a54ca4ec
quay/quay-rhel8@sha256:986d7f4f84f0f9ef3e8146fed3a76e1c4f541dbb83e813d6cb8ceedb9bddcb2e

x86_64

quay/clair-rhel8@sha256:fe89f9ff7267f4d92a0403e7b8c51fb4aaa144a9c427768d193d5a04637033e7
quay/quay-bridge-operator-bundle@sha256:a78c4b39ed53ec663e09de75f8bde4c6af3b3f395228ab77133bd86f6181884e
quay/quay-bridge-operator-rhel8@sha256:0f138f897586122a750889380db8944e933367f0a782a4f9e0fbbc41d03a0cd9
quay/quay-builder-qemu-rhcos-rhel8@sha256:4015d451079ea928f8a782d954fbe07cf62d072a44c62caefccc7af6cb1f6795
quay/quay-builder-rhel8@sha256:35efc1093afb5799903b1852051f5b4282ce80dc47771d16b039c33e25ea467a
quay/quay-container-security-operator-bundle@sha256:1162b077c36704a466dc62ddd6f5d8e82f3bc892cf84dcacee3403d091eaaba3
quay/quay-container-security-operator-rhel8@sha256:279abe55b8862328cfc6e30a532328ab8ab62cd798b466404dc645d2fb9c7099
quay/quay-operator-bundle@sha256:6337c0cbc7fbb36a652f14df127ec97aa14a11b37d5e5cadec6a9e13d7ee1115
quay/quay-operator-rhel8@sha256:6af6847675f862147c2aeb581a5c5931f4c61e567772c5f1ad9757011abd4bc5
quay/quay-rhel8@sha256:fcece67d0a7d2cba34d8f94d73bb716076b472ae7a687b9718875ec569eb51d9

The Red Hat security contact is secalert@redhat.com. More contact details at https://access.redhat.com/security/team/contact/.

Red Hat LinkedIn YouTube Facebook X, formerly Twitter

Quick Links

  • Downloads
  • Subscriptions
  • Support Cases
  • Customer Service
  • Product Documentation

Help

  • Contact Us
  • Customer Portal FAQ
  • Log-in Assistance

Site Info

  • Trust Red Hat
  • Browser Support Policy
  • Accessibility
  • Awards and Recognition
  • Colophon

Related Sites

  • redhat.com
  • developers.redhat.com
  • connect.redhat.com
  • cloud.redhat.com

Red Hat legal and privacy links

  • About Red Hat
  • Jobs
  • Events
  • Locations
  • Contact Red Hat
  • Red Hat Blog
  • Inclusion at Red Hat
  • Cool Stuff Store
  • Red Hat Summit
© 2025 Red Hat

Red Hat legal and privacy links

  • Privacy statement
  • Terms of use
  • All policies and guidelines
  • Digital accessibility