RHSA-2025:22623HighCVSS 9.0
Red Hat Security Advisory: Red Hat OpenShift Dev Spaces 3.24.1 Release.
🔗 CVE IDs covered (1)
📋 Description
CVE-2025-12548 — github.com/che-incubator/che-code: Eclipse Che — unauthenticated RCE and secret exfiltration via TCP/3333
🎯 Affected products6
- Red Hat OpenShift Dev Spaces (RHOSDS) 3.24
- registry.redhat.io/devspaces/code-rhel9@sha256:18e08f6cf87349707efe99e95b1029ff084f0824ab16515aac98302dda906eea_ppc64le as a component of Red Hat OpenShift Dev Spaces (RHOSDS) 3.24
- registry.redhat.io/devspaces/code-rhel9@sha256:55205f8b22e78021ebb4beff25c4d250a359629cf96bea4afb5b633f124d6d50_s390x as a component of Red Hat OpenShift Dev Spaces (RHOSDS) 3.24
- registry.redhat.io/devspaces/code-rhel9@sha256:9135e1c02a4f67bbd80fa6755cab3096aa5ecefabdc9af39c700f52ca24d2c6e_arm64 as a component of Red Hat OpenShift Dev Spaces (RHOSDS) 3.24
- registry.redhat.io/devspaces/code-rhel9@sha256:ced0e45c01cb5f473deb4fb137249b743b907d27172fbabd223024c4000ba56f_amd64 as a component of Red Hat OpenShift Dev Spaces (RHOSDS) 3.24
- registry.redhat.io/devspaces/devspaces-operator-bundle@sha256:69b9d5c8a2a342b223e21d7d40b179fde917e254193c709c34f9a11c24733391_amd64 as a component of Red Hat OpenShift Dev Spaces (RHOSDS) 3.24
✅ Remediation
Before applying this update, make sure all previously released errata relevant to your system have been applied. For details on how to apply this update, refer to: https://access.redhat.com/articles/11258 Workaround: Apply the security best practices from the Red Hat OpenShift Dev Spaces Administration Guide: https://docs.redhat.com/en/documentation/red_hat_openshift_dev_spaces/3.24/html/administration_guide/security-best-practices
🔗 References (5)
- selfhttps://access.redhat.com/errata/RHSA-2025:22623
- externalhttps://access.redhat.com/documentation/en-us/red_hat_openshift_dev_spaces/3.24/html/administration_guide/installing-devspaces
- externalhttps://access.redhat.com/security/cve/CVE-2025-12548
- externalhttps://access.redhat.com/security/updates/classification/
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2025/rhsa-2025_22623.json