Red Hat Bug Fix Advisory: Red Hat Quay v3.13.6 bug fix release
Red Hat Quay version 3.14.2 was released as a bug fix update addressing issues including CVE-2025-4374. The update is rated with an Important security impact by Red Hat Product Security. The advisory mentions fixes related to UI tag history display and references CVE-2025-4374 along with CVE-2020-13790. No detailed CVSS score or exploit information is provided. Users are advised to apply this update after ensuring all previous errata are applied.
AI Analysis
Technical Summary
Red Hat Quay 3.14.2 is a bug fix release that addresses security and functional issues, including the vulnerability identified as CVE-2025-4374. The vulnerability is associated with CWE-266 (likely related to permissions or access control). The update is classified as having an Important security impact by Red Hat Product Security. The advisory does not provide a CVSS score or detailed technical exploit information. The update also fixes a UI bug (PROJQUAY-8633) related to tag history date display. Users should apply this update following Red Hat's guidance and after applying all prior relevant errata.
Potential Impact
The vulnerability CVE-2025-4374 affects Red Hat Quay and is considered to have an Important security impact. CWE-266 suggests it relates to permissions or access control issues, which could potentially allow unauthorized actions if exploited. No known exploits are reported in the wild. The update addresses these issues to improve security and functionality.
Mitigation Recommendations
Red Hat has released Quay version 3.14.2 containing fixes for CVE-2025-4374 and other bugs. Users should apply this update to remediate the vulnerability. Before updating, ensure all previously released errata relevant to the system are applied. Follow Red Hat's official update instructions at https://access.redhat.com/articles/11258. No additional mitigation steps are indicated by the vendor advisory.
Red Hat Bug Fix Advisory: Red Hat Quay v3.13.6 bug fix release
Description
Red Hat Quay version 3.14.2 was released as a bug fix update addressing issues including CVE-2025-4374. The update is rated with an Important security impact by Red Hat Product Security. The advisory mentions fixes related to UI tag history display and references CVE-2025-4374 along with CVE-2020-13790. No detailed CVSS score or exploit information is provided. Users are advised to apply this update after ensuring all previous errata are applied.
Affected software
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
Red Hat Quay 3.14.2 is a bug fix release that addresses security and functional issues, including the vulnerability identified as CVE-2025-4374. The vulnerability is associated with CWE-266 (likely related to permissions or access control). The update is classified as having an Important security impact by Red Hat Product Security. The advisory does not provide a CVSS score or detailed technical exploit information. The update also fixes a UI bug (PROJQUAY-8633) related to tag history date display. Users should apply this update following Red Hat's guidance and after applying all prior relevant errata.
Potential Impact
The vulnerability CVE-2025-4374 affects Red Hat Quay and is considered to have an Important security impact. CWE-266 suggests it relates to permissions or access control issues, which could potentially allow unauthorized actions if exploited. No known exploits are reported in the wild. The update addresses these issues to improve security and functionality.
Mitigation Recommendations
Red Hat has released Quay version 3.14.2 containing fixes for CVE-2025-4374 and other bugs. Users should apply this update to remediate the vulnerability. Before updating, ensure all previously released errata relevant to the system are applied. Follow Red Hat's official update instructions at https://access.redhat.com/articles/11258. No additional mitigation steps are indicated by the vendor advisory.
Technical Details
- Gcve Source
- db.gcve.eu
- Csaf Category
- csaf_security_advisory
- Csaf Version
- 2.0
- Publisher
- Red Hat Product Security
- Advisory Id
- RHBA-2025:8262
- Cve Count
- 1
- Additional Cves
- []
- Cvss Version
- null
Threat ID: 6a74cf98bf8831d5391afda3
Added to database: 08/06/2026, 18:16:56 UTC
Last enriched: 08/06/2026, 18:47:24 UTC
Last updated: 08/06/2026, 22:40:59 UTC
Views: 1
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.