RHSA-2025:22623HighCVSS 9.0

Red Hat Security Advisory: Red Hat OpenShift Dev Spaces 3.24.1 Release.

Published
December 2, 2025
Last Modified
August 2, 2026

🔗 CVE IDs covered (1)

📋 Description

CVE-2025-12548 — github.com/che-incubator/che-code: Eclipse Che — unauthenticated RCE and secret exfiltration via TCP/3333

🎯 Affected products6

  • Red Hat OpenShift Dev Spaces (RHOSDS) 3.24
  • registry.redhat.io/devspaces/code-rhel9@sha256:18e08f6cf87349707efe99e95b1029ff084f0824ab16515aac98302dda906eea_ppc64le as a component of Red Hat OpenShift Dev Spaces (RHOSDS) 3.24
  • registry.redhat.io/devspaces/code-rhel9@sha256:55205f8b22e78021ebb4beff25c4d250a359629cf96bea4afb5b633f124d6d50_s390x as a component of Red Hat OpenShift Dev Spaces (RHOSDS) 3.24
  • registry.redhat.io/devspaces/code-rhel9@sha256:9135e1c02a4f67bbd80fa6755cab3096aa5ecefabdc9af39c700f52ca24d2c6e_arm64 as a component of Red Hat OpenShift Dev Spaces (RHOSDS) 3.24
  • registry.redhat.io/devspaces/code-rhel9@sha256:ced0e45c01cb5f473deb4fb137249b743b907d27172fbabd223024c4000ba56f_amd64 as a component of Red Hat OpenShift Dev Spaces (RHOSDS) 3.24
  • registry.redhat.io/devspaces/devspaces-operator-bundle@sha256:69b9d5c8a2a342b223e21d7d40b179fde917e254193c709c34f9a11c24733391_amd64 as a component of Red Hat OpenShift Dev Spaces (RHOSDS) 3.24

✅ Remediation

Before applying this update, make sure all previously released errata relevant to your system have been applied. For details on how to apply this update, refer to: https://access.redhat.com/articles/11258 Workaround: Apply the security best practices from the Red Hat OpenShift Dev Spaces Administration Guide: https://docs.redhat.com/en/documentation/red_hat_openshift_dev_spaces/3.24/html/administration_guide/security-best-practices

🔗 References (5)