RHSA-2025:22652HighCVSS 9.0
Red Hat Security Advisory: Red Hat OpenShift Dev Spaces 3.23.1 Release.
🔗 CVE IDs covered (1)
📋 Description
CVE-2025-12548 — github.com/che-incubator/che-code: Eclipse Che — unauthenticated RCE and secret exfiltration via TCP/3333
🎯 Affected products6
- Red Hat OpenShift Dev Spaces (RHOSDS) 3.23
- registry.redhat.io/devspaces/code-rhel9@sha256:4b9159902333a82353bf91823c092e9e2508b17b92e8c6fe0295b5a6609f25f3_s390x as a component of Red Hat OpenShift Dev Spaces (RHOSDS) 3.23
- registry.redhat.io/devspaces/code-rhel9@sha256:530cc2d4545285c5049faa1d379d57c1f0b00f34ec962fae78778893a7fdab50_arm64 as a component of Red Hat OpenShift Dev Spaces (RHOSDS) 3.23
- registry.redhat.io/devspaces/code-rhel9@sha256:83bdc106e7049b40977f8407a1b305be91afdd555a08ab097e448205c9f24eac_ppc64le as a component of Red Hat OpenShift Dev Spaces (RHOSDS) 3.23
- registry.redhat.io/devspaces/code-rhel9@sha256:a6fe7e233fa23e1fff9c74c5d4cbe800534561131b5be59533e88ede24452e3a_amd64 as a component of Red Hat OpenShift Dev Spaces (RHOSDS) 3.23
- registry.redhat.io/devspaces/devspaces-operator-bundle@sha256:48c3048fafcdcf5d50fb5a5760e21b9fe062ec791c6ca9f288a9bcc556677f25_amd64 as a component of Red Hat OpenShift Dev Spaces (RHOSDS) 3.23
✅ Remediation
Before applying this update, make sure all previously released errata relevant to your system have been applied. For details on how to apply this update, refer to: https://access.redhat.com/articles/11258 Workaround: Apply the security best practices from the Red Hat OpenShift Dev Spaces Administration Guide: https://docs.redhat.com/en/documentation/red_hat_openshift_dev_spaces/3.24/html/administration_guide/security-best-practices
🔗 References (5)
- selfhttps://access.redhat.com/errata/RHSA-2025:22652
- externalhttps://access.redhat.com/documentation/en-us/red_hat_openshift_dev_spaces/3.23/html/administration_guide/installing-devspaces
- externalhttps://access.redhat.com/security/cve/CVE-2025-12548
- externalhttps://access.redhat.com/security/updates/classification/
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2025/rhsa-2025_22652.json