RHBA-2025:0409HighCVSS 8.0

Red Hat Bug Fix Advisory: Red Hat Developer Hub 1.4.1 release.

Published
January 20, 2025
Last Modified
August 22, 2026

🔗 CVE IDs covered (6)

📋 Description

CVE-2024-45338 — golang.org/x/net/html: Non-linear parsing of case-insensitive content in golang.org/x/net/html CVE-2024-52798 — path-to-regexp: path-to-regexp Unpatched path-to-regexp ReDoS in 0.1.x CVE-2024-55565 — nanoid: nanoid mishandles non-integer values CVE-2024-56201 — jinja2: Jinja has a sandbox breakout through malicious filenames CVE-2024-56326 — jinja2: Jinja has a sandbox breakout through indirect reference to format method CVE-2024-56334 — systeminformation: Command injection vulnerability in getWindowsIEEE8021x (SSID) function in systeminformation

🎯 Affected products4

  • Red Hat Developer Hub (RHDH) 1.4
  • registry.redhat.io/rhdh/rhdh-hub-rhel9@sha256:d8268197ba0466643efb818fcad8f0fc29e32463f75b0f7f51d9ce75ec717572_amd64 as a component of Red Hat Developer Hub (RHDH) 1.4
  • registry.redhat.io/rhdh/rhdh-operator-bundle@sha256:a91c4931ef5111c555ec5cc8128c3148c94fe2983d2e4fa7babe843e9292b303_amd64 as a component of Red Hat Developer Hub (RHDH) 1.4
  • registry.redhat.io/rhdh/rhdh-rhel9-operator@sha256:9e1e2fac9519bd480c9629f5a9cf69be0169715483b7e662eaac61a48b37eb60_amd64 as a component of Red Hat Developer Hub (RHDH) 1.4

✅ Remediation

For more about Red Hat Developer Hub, see References links Workaround: Avoid using two parameters within a single path segment when the separator is not, for example, /:a-:b. Alternatively, you can define the regex used for both parameters and ensure they do not overlap to allow backtracking. Workaround: To mitigate this vulnerabilty restrict user-controlled template filenames, ensuring they follow a predefined templates. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.

🔗 References (11)