RHSA-2025:14767HighCVSS 7.7
Red Hat Security Advisory: Red Hat Developer Hub 1.6.4 release.
🔗 CVE IDs covered (3)
📋 Description
CVE-2025-7338 — multer: Multer Denial of Service CVE-2025-9287 — cipher-base: Cipher-base hash manipulation CVE-2025-9288 — sha.js: Missing type checks leading to hash rewind and passing on crafted data
🎯 Affected products4
- RHDH 1.6
- registry.redhat.io/rhdh/rhdh-hub-rhel9@sha256:48b72d96926999336505cbf097f873dd9ccb2dec814a5db7f7ffa630dea29dc5_amd64 as a component of RHDH 1.6
- registry.redhat.io/rhdh/rhdh-operator-bundle@sha256:7de394929c58edb75ef46b277a25322f77f098919208eca5694c927c38c5af26_amd64 as a component of RHDH 1.6
- registry.redhat.io/rhdh/rhdh-rhel9-operator@sha256:555e8b3628e6f2bad033545016f774a7bf5f01d038a2c4696982067964a56cb8_amd64 as a component of RHDH 1.6
✅ Remediation
For more about Red Hat Developer Hub, see References links Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.
🔗 References (12)
- selfhttps://access.redhat.com/errata/RHSA-2025:14767
- externalhttps://access.redhat.com/security/cve/CVE-2025-7338
- externalhttps://access.redhat.com/security/cve/CVE-2025-9287
- externalhttps://access.redhat.com/security/cve/CVE-2025-9288
- externalhttps://access.redhat.com/security/updates/classification/
- externalhttps://catalog.redhat.com/search?gs&searchType=containers&q=rhdh
- externalhttps://developers.redhat.com/rhdh/overview
- externalhttps://docs.redhat.com/en/documentation/red_hat_developer_hub
- externalhttps://issues.redhat.com/browse/RHIDP-8263
- externalhttps://issues.redhat.com/browse/RHIDP-8678
- externalhttps://issues.redhat.com/browse/RHIDP-8684
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2025/rhsa-2025_14767.json