RHBA-2024:9054HighCVSS 7.5

Red Hat Bug Fix Advisory: Red Hat Developer Hub 1.3.1 bugfix release

Published
November 11, 2024
Last Modified
August 24, 2026

🔗 CVE IDs covered (3)

📋 Description

CVE-2024-21536 — http-proxy-middleware: Denial of Service CVE-2024-37890 — nodejs-ws: denial of service when handling a request with many HTTP headers CVE-2024-45590 — body-parser: Denial of Service Vulnerability in body-parser

🎯 Affected products4

  • Red Hat Developer Hub 1.3 for RHEL 9
  • rhdh/rhdh-hub-rhel9@sha256:9bf03585d9a90ad7ba0dd56e9210dbe099be187e9ada06b2a2ca754cefa89314_amd64 as a component of Red Hat Developer Hub 1.3 for RHEL 9
  • rhdh/rhdh-operator-bundle@sha256:aa2551561078f59c2ac06905bbe51601a438bd8534c5240657964d6e3b685295_amd64 as a component of Red Hat Developer Hub 1.3 for RHEL 9
  • rhdh/rhdh-rhel9-operator@sha256:8d3e75e17444a5b5b8ffa103b7c880132b2e814245d438363f5434d5d4be1167_amd64 as a component of Red Hat Developer Hub 1.3 for RHEL 9

✅ Remediation

To install the Red Hat Developer Hub 1.3, follow the instructions linked from the References section. Workaround: Red Hat Product Security does not have any mitigation recommendations at this time. Workaround: The issue can be mitigated by reducing the maximum allowed length of the request headers using the --max-http-header-size=size or the maxHeaderSize options so that no more headers than the server.maxHeadersCount limit can be sent. The issue can be mitigated also by seting server.maxHeadersCount to 0. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.

🔗 References (5)