RHBA-2024:4924MediumCVSS 6.5
Red Hat Bug Fix Advisory: Red Hat Developer Hub 1.2.2 bugfix release
🔗 CVE IDs covered (1)
📋 Description
CVE-2024-28863 — node-tar: denial of service while parsing a tar file due to lack of folders depth validation
🎯 Affected products4
- Red Hat Developer Hub 1.2 for RHEL 9
- rhdh/rhdh-hub-rhel9@sha256:6b70449451b17941dd5b1cdedb764aaab2c945b5c5b432cfc97c1e07e35b7aa2_amd64 as a component of Red Hat Developer Hub 1.2 for RHEL 9
- rhdh/rhdh-operator-bundle@sha256:da263929d3a8cbc701de44f786d8c5fe3f9768dad270a1b34d8ff08e670785f0_amd64 as a component of Red Hat Developer Hub 1.2 for RHEL 9
- rhdh/rhdh-rhel9-operator@sha256:c9792288095a9b9db5e1f9ad5365985a0582f2fa097f8bc72b0ca1cdb52830a1_amd64 as a component of Red Hat Developer Hub 1.2 for RHEL 9
✅ Remediation
Before applying this update, make sure all previously released errata relevant to your system have been applied. For details on how to apply this update, refer to: https://access.redhat.com/articles/11258