RHBA-2024:4924MediumCVSS 6.5

Red Hat Bug Fix Advisory: Red Hat Developer Hub 1.2.2 bugfix release

Published
July 30, 2024
Last Modified
July 29, 2026

🔗 CVE IDs covered (1)

📋 Description

CVE-2024-28863 — node-tar: denial of service while parsing a tar file due to lack of folders depth validation

🎯 Affected products4

  • Red Hat Developer Hub 1.2 for RHEL 9
  • rhdh/rhdh-hub-rhel9@sha256:6b70449451b17941dd5b1cdedb764aaab2c945b5c5b432cfc97c1e07e35b7aa2_amd64 as a component of Red Hat Developer Hub 1.2 for RHEL 9
  • rhdh/rhdh-operator-bundle@sha256:da263929d3a8cbc701de44f786d8c5fe3f9768dad270a1b34d8ff08e670785f0_amd64 as a component of Red Hat Developer Hub 1.2 for RHEL 9
  • rhdh/rhdh-rhel9-operator@sha256:c9792288095a9b9db5e1f9ad5365985a0582f2fa097f8bc72b0ca1cdb52830a1_amd64 as a component of Red Hat Developer Hub 1.2 for RHEL 9

✅ Remediation

Before applying this update, make sure all previously released errata relevant to your system have been applied. For details on how to apply this update, refer to: https://access.redhat.com/articles/11258

🔗 References (3)