RHSA-2025:10992HighCVSS 7.3
Red Hat Security Advisory: Red Hat Developer Hub 1.5.3 release.
🔗 CVE IDs covered (2)
📋 Description
CVE-2025-47273 — setuptools: Path Traversal Vulnerability in setuptools PackageIndex CVE-2025-48387 — tar-fs: tar-fs has issue where extract can write outside the specified dir with a specific tarball
🎯 Affected products4
- RHDH 1.5
- registry.redhat.io/rhdh/rhdh-hub-rhel9@sha256:1d4c7fa815e480d838f9e375c65e78ef0e851ce093c84483a994673129d4643c_amd64 as a component of RHDH 1.5
- registry.redhat.io/rhdh/rhdh-operator-bundle@sha256:5a19032dda9a0f584b41cbe9e729ed23e6003d90ebbb026eb9e7bb9769d4a4e4_amd64 as a component of RHDH 1.5
- registry.redhat.io/rhdh/rhdh-rhel9-operator@sha256:46c6d246831d26833d5381afd555f36bb52a8cb02fc025c06042983021c20222_amd64 as a component of RHDH 1.5
✅ Remediation
For more about Red Hat Developer Hub, see References links Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability. Workaround: Mitigation is either unavailable or does not meet Red Hat Product Security standards for usability, deployment, applicability, or stability.
🔗 References (10)
- selfhttps://access.redhat.com/errata/RHSA-2025:10992
- externalhttps://access.redhat.com/security/cve/CVE-2025-47273
- externalhttps://access.redhat.com/security/cve/CVE-2025-48387
- externalhttps://access.redhat.com/security/updates/classification/
- externalhttps://catalog.redhat.com/search?gs&searchType=containers&q=rhdh
- externalhttps://developers.redhat.com/rhdh/overview
- externalhttps://docs.redhat.com/en/documentation/red_hat_developer_hub
- externalhttps://issues.redhat.com/browse/RHIDP-7702
- externalhttps://issues.redhat.com/browse/RHIDP-7793
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2025/rhsa-2025_10992.json