Red Hat Security Advisory: Red Hat Developer Hub 1.7.0 release.
🔗 CVE IDs covered (9)
📋 Description
CVE-2025-5417 — rhdh: Red Hat Developer Hub user permissions CVE-2025-6545 — pbkdf2: pbkdf2 silently returns predictable key material CVE-2025-7338 — multer: Multer Denial of Service CVE-2025-22870 — golang.org/x/net/proxy: golang.org/x/net/http/httpproxy: HTTP Proxy bypass using IPv6 Zone IDs in golang.org/x/net CVE-2025-32996 — http-proxy-middleware: Always-Incorrect Control Flow Implementation in http-proxy-middleware CVE-2025-32997 — http-proxy-middleware: Improper Check for Unusual or Exceptional Conditions in http-proxy-middleware CVE-2025-48387 — tar-fs: tar-fs has issue where extract can write outside the specified dir with a specific tarball CVE-2025-48997 — multer: Multer vulnerable to Denial of Service via unhandled exception CVE-2025-54419 — @node-saml/node-saml: Node-SAML Signature Verification Vulnerability
🔗 References (18)
- selfhttps://access.redhat.com/errata/RHSA-2025:14090
- externalhttps://access.redhat.com/security/cve/CVE-2025-22870
- externalhttps://access.redhat.com/security/cve/CVE-2025-32996
- externalhttps://access.redhat.com/security/cve/CVE-2025-32997
- externalhttps://access.redhat.com/security/cve/CVE-2025-48387
- externalhttps://access.redhat.com/security/cve/CVE-2025-48997
- externalhttps://access.redhat.com/security/cve/CVE-2025-5417
- externalhttps://access.redhat.com/security/cve/CVE-2025-54419
- externalhttps://access.redhat.com/security/cve/CVE-2025-6545
- externalhttps://access.redhat.com/security/cve/CVE-2025-7338
- externalhttps://access.redhat.com/security/updates/classification/
- externalhttps://catalog.redhat.com/search?gs&searchType=containers&q=rhdh
- externalhttps://developers.redhat.com/rhdh/overview
- externalhttps://docs.redhat.com/en/documentation/red_hat_developer_hub
- externalhttps://issues.redhat.com/browse/RHIDP-6469
- externalhttps://issues.redhat.com/browse/RHIDP-6470
- externalhttps://issues.redhat.com/browse/RHIDP-6937
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2025/rhsa-2025_14090.json