Red Hat Bug Fix Advisory: Red Hat Developer Hub 1.3.0 release
🔗 CVE IDs covered (11)
📋 Description
CVE-2024-4067 — micromatch: vulnerable to Regular Expression Denial of Service CVE-2024-4068 — braces: fails to limit the number of characters it can handle CVE-2024-21529 — dset: Prototype Pollution CVE-2024-24790 — golang: net/netip: Unexpected behavior from Is methods for IPv4-mapped IPv6 addresses CVE-2024-24791 — net/http: Denial of service due to improper 100-continue handling in net/http CVE-2024-35255 — azure-identity: Azure Identity Libraries Elevation of Privilege Vulnerability in github.com/Azure/azure-sdk-for-go/sdk/azidentity CVE-2024-37891 — urllib3: proxy-authorization request header is not stripped during cross-origin redirects CVE-2024-39008 — fast-loops: prototype pollution via objectMergeDeep CVE-2024-39249 — nodejs-async: Regular expression denial of service while parsing function in autoinject CVE-2024-43796 — express: Improper Input Handling in Express Redirects CVE-2024-43800 — serve-static: Improper Sanitization in serve-static
🎯 Affected products4
- Red Hat Developer Hub 1.3 for RHEL 9
- rhdh/rhdh-hub-rhel9@sha256:ccc2f05dd6dacbe9b39bbe5b4774ef9d61b872fa7c26e47c0c63d260920ad436_amd64 as a component of Red Hat Developer Hub 1.3 for RHEL 9
- rhdh/rhdh-operator-bundle@sha256:717ddb1edb2f3ba94fa68d5310dfe2c0b4aa0a3a75747011b1cd4d6956d982e3_amd64 as a component of Red Hat Developer Hub 1.3 for RHEL 9
- rhdh/rhdh-rhel9-operator@sha256:4984c6cc3d35be00fa8758b2ddbb2712ad0085b557ff1bac9cc885a47bc20bf4_amd64 as a component of Red Hat Developer Hub 1.3 for RHEL 9
✅ Remediation
Before applying this update, make sure all previously released errata relevant to your system have been applied. For details on how to apply this update, refer to: https://access.redhat.com/articles/11258 Workaround: Mitigation for this issue is either not available or the currently available options don't meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.