RHSA-2025:1931MediumCVSS 6.8
Red Hat Security Advisory: Red Hat Developer Hub 1.4.2 release.
🔗 CVE IDs covered (2)
📋 Description
CVE-2024-30261 — nodejs-undici: fetch() with integrity option is too lax when algorithm is specified but hash value is in incorrect CVE-2025-22150 — undici: Undici Uses Insufficiently Random Values
🎯 Affected products4
- Red Hat Developer Hub (RHDH) 1.4
- registry.redhat.io/rhdh/rhdh-hub-rhel9@sha256:5eb109362246ccddd564febe6387bc6015d47555df00c36aa88c2247099851b7_amd64 as a component of Red Hat Developer Hub (RHDH) 1.4
- registry.redhat.io/rhdh/rhdh-operator-bundle@sha256:c3fcfee584652ee840c655ac4dd141743bafd5043865f20dd78116bc33e9e850_amd64 as a component of Red Hat Developer Hub (RHDH) 1.4
- registry.redhat.io/rhdh/rhdh-rhel9-operator@sha256:8de6cdad90f1afd72dbc6637a6a14bdeedc7b909654a3913c4f44e518d6b22ef_amd64 as a component of Red Hat Developer Hub (RHDH) 1.4
✅ Remediation
For more about Red Hat Developer Hub, see References links Workaround: Mitigation for this issue is either not available or the currently available options don't meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.
🔗 References (8)
- selfhttps://access.redhat.com/errata/RHSA-2025:1931
- externalhttps://access.redhat.com/security/cve/CVE-2025-22150
- externalhttps://access.redhat.com/security/cve/CVE-2024-30261
- externalhttps://access.redhat.com/security/updates/classification/
- externalhttps://catalog.redhat.com/search?gs&searchType=containers&q=rhdh
- externalhttps://developers.redhat.com/rhdh/overview
- externalhttps://docs.redhat.com/en/documentation/red_hat_developer_hub
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2025/rhsa-2025_1931.json