RHBA-2024:10184HighCVSS 7.5
Red Hat Bug Fix Advisory: Red Hat Developer Hub 1.2.5 bugfix release
🔗 CVE IDs covered (2)
📋 Description
CVE-2023-46234 — browserify-sign: upper bound check issue in dsaVerify leads to a signature forgery attack CVE-2024-43799 — send: Code Execution Vulnerability in Send Library
🎯 Affected products4
- Red Hat Developer Hub 1.2 for RHEL 9
- rhdh/rhdh-hub-rhel9@sha256:f767bbaa49d570a56a56bf0a645dcedd3ffa2708eba0ec15bfad7ff945bb32e0_amd64 as a component of Red Hat Developer Hub 1.2 for RHEL 9
- rhdh/rhdh-operator-bundle@sha256:808b5e941f390c695cb713b86066ff833537ce7c3e387c2c260f0aecdeae30d6_amd64 as a component of Red Hat Developer Hub 1.2 for RHEL 9
- rhdh/rhdh-rhel9-operator@sha256:a311b97bd9d865a028653f9dd754b32aabe60ca128c5b97d899b6c81a24000e5_amd64 as a component of Red Hat Developer Hub 1.2 for RHEL 9
✅ Remediation
For more information about Red Hat Developer Hub 1.2, see the link in the References section. Workaround: No current mitigation is yet available for this flaw. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.
🔗 References (6)
- selfhttps://access.redhat.com/errata/RHBA-2024:10184
- externalhttps://docs.redhat.com/en/documentation/red_hat_developer_hub/1.2
- externalhttps://issues.redhat.com/browse/RHIDP-4215
- externalhttps://issues.redhat.com/browse/RHIDP-4217
- externalhttps://issues.redhat.com/browse/RHIDP-4218
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2024/rhba-2024_10184.json