RHSA-2025:14474HighCVSS 8.1
Red Hat Security Advisory: RHTAS 1.2.1- Red Hat Trusted Artifact Signer Release
🔗 CVE IDs covered (3)
📋 Description
CVE-2025-6545 — pbkdf2: pbkdf2 silently returns predictable key material CVE-2025-6547 — pbkdf2: pbkdf2 silently returns static keys CVE-2025-9288 — sha.js: Missing type checks leading to hash rewind and passing on crafted data
🔗 References (8)
- selfhttps://access.redhat.com/errata/RHSA-2025:14474
- externalhttps://access.redhat.com/documentation/en-us/red_hat_trusted_artifact_signer/1.2
- externalhttps://access.redhat.com/documentation/en-us/red_hat_trusted_artifact_signer/1.2/html-single/release_notes/index
- externalhttps://access.redhat.com/security/cve/CVE-2025-6545
- externalhttps://access.redhat.com/security/cve/CVE-2025-6547
- externalhttps://access.redhat.com/security/cve/CVE-2025-9288
- externalhttps://access.redhat.com/security/updates/classification/
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2025/rhsa-2025_14474.json