RHSA-2025:22404HighCVSS 8.2

Red Hat Security Advisory: Red Hat Developer Hub 1.7.3 release.

Published
December 1, 2025
Last Modified
August 9, 2026

🔗 CVE IDs covered (1)

📋 Description

CVE-2025-60542 — TypeORM: SQL Injection via crafted request to repository.save or repository.update

🎯 Affected products4

  • Red Hat Developer Hub 1.7
  • registry.redhat.io/rhdh/rhdh-hub-rhel9@sha256:bedacfa68d74fce1e9efe3a3fdb18963f4e648d7ab6ccf34b868d62d9f25304a_amd64 as a component of Red Hat Developer Hub 1.7
  • registry.redhat.io/rhdh/rhdh-operator-bundle@sha256:54c5cd2a4865a372ba9465908f73928382745e04ad446c97b28adde213d13309_amd64 as a component of Red Hat Developer Hub 1.7
  • registry.redhat.io/rhdh/rhdh-rhel9-operator@sha256:f45ee5600c84c3d014c8bfb9a06e3b600acaa74ce8ff4bf12e5124d25cbe5bfe_amd64 as a component of Red Hat Developer Hub 1.7

✅ Remediation

For more about Red Hat Developer Hub, see References links Workaround: Red Hat has investigated whether a possible mitigation exists for this issue, and has not been able to identify a practical example. Please update the affected package as soon as possible.

🔗 References (9)