Red Hat Security Advisory: Red Hat OpenShift Dev Spaces 3.25.0 Release.
🔗 CVE IDs covered (7)
📋 Description
CVE-2024-4067 — micromatch: vulnerable to Regular Expression Denial of Service CVE-2025-55247 — dotnet: .NET Denial of Service Vulnerability CVE-2025-55248 — dotnet: .NET Information Disclosure Vulnerability CVE-2025-55315 — dotnet: .NET Security Feature Bypass Vulnerability CVE-2025-55752 — tomcat: org.apache.tomcat/tomcat-catalina: Apache Tomcat: Directory traversal via rewrite with possible RCE CVE-2025-61927 — happy-dom: Happy-DOM VM Context Escape CVE-2025-66516 — tika-core: tika-parsers: tika-parser-pdf-module: Apache Tika core, Apache Tika parsers, Apache Tika PDF parser module: Update to CVE-2025-54988 to expand scope of artifacts affected
🎯 Affected products62
- Red Hat OpenShift Dev Spaces (RHOSDS) 3.25
- registry.redhat.io/devspaces/code-rhel9@sha256:46811ca65f64fb6d260e3dca253947c749b6dd31ce3185f36e729ea817f454a4_ppc64le as a component of Red Hat OpenShift Dev Spaces (RHOSDS) 3.25
- registry.redhat.io/devspaces/code-rhel9@sha256:65b5989d68b4489a7d1b915870afc49c0f977b9690ee958be7e8fedcc611087f_amd64 as a component of Red Hat OpenShift Dev Spaces (RHOSDS) 3.25
- registry.redhat.io/devspaces/code-rhel9@sha256:7d38a9fe7e1bf493f235c62ebaabdc1c805b94e731186b9ffa56cf581abc8f77_arm64 as a component of Red Hat OpenShift Dev Spaces (RHOSDS) 3.25
- registry.redhat.io/devspaces/code-rhel9@sha256:869bac1a7cc51c0a780667abd7b47f9e42f2da22e6d6a57b5a1d7ecdeddcee7c_s390x as a component of Red Hat OpenShift Dev Spaces (RHOSDS) 3.25
- registry.redhat.io/devspaces/code-sshd-rhel9@sha256:0a15c7b78d69e8711f81727879c1d4bbd8c2e8547a0b5c84513ea3a42fb5f8f3_arm64 as a component of Red Hat OpenShift Dev Spaces (RHOSDS) 3.25
- registry.redhat.io/devspaces/code-sshd-rhel9@sha256:e34005d1fc54aaf8863c5f0bf4bdd30120e65df1a61a6e775f0998e0be152582_ppc64le as a component of Red Hat OpenShift Dev Spaces (RHOSDS) 3.25
- registry.redhat.io/devspaces/code-sshd-rhel9@sha256:e381c47978265d9db3daf279657a63cfe8f1f5afe0d00d4792b819cbae480338_amd64 as a component of Red Hat OpenShift Dev Spaces (RHOSDS) 3.25
- registry.redhat.io/devspaces/code-sshd-rhel9@sha256:fdbae1704685d51d583b0c2e588ddf3b088b78cc84b239821421042c0943c098_s390x as a component of Red Hat OpenShift Dev Spaces (RHOSDS) 3.25
- registry.redhat.io/devspaces/configbump-rhel9@sha256:969198cbaa319f55733ae4fb378b867f8afb9d1bfe78dfce65b20fd7ac9fb541_arm64 as a component of Red Hat OpenShift Dev Spaces (RHOSDS) 3.25
- registry.redhat.io/devspaces/configbump-rhel9@sha256:a1ccad11e91784e0b6ed9eb1745d86c8783f1e869096a7f735f47280df0acc4e_amd64 as a component of Red Hat OpenShift Dev Spaces (RHOSDS) 3.25
- registry.redhat.io/devspaces/configbump-rhel9@sha256:b2c13795589df33fec7a6c6b5ed37e11db14f134bfcc7ee0350e3df372f5da88_ppc64le as a component of Red Hat OpenShift Dev Spaces (RHOSDS) 3.25
- registry.redhat.io/devspaces/configbump-rhel9@sha256:e6f11881adb8f1675e5e3372339e648d99084d7d3f244d0de1eeebc96ed08dfc_s390x as a component of Red Hat OpenShift Dev Spaces (RHOSDS) 3.25
- registry.redhat.io/devspaces/dashboard-rhel9@sha256:6137931395a4cbfa07e5579172ed579babd14a2d1e054238298eee1aee4e2c07_ppc64le as a component of Red Hat OpenShift Dev Spaces (RHOSDS) 3.25
- registry.redhat.io/devspaces/dashboard-rhel9@sha256:804b00736484cc574e738130b9dc0e553828f54705fed29dbd9bb873bc5d1baa_arm64 as a component of Red Hat OpenShift Dev Spaces (RHOSDS) 3.25
- registry.redhat.io/devspaces/dashboard-rhel9@sha256:8cf6cd46eef5fea2e500e14b18a8ec545b5bec93e6fb2289a9d760d56e4b52bb_amd64 as a component of Red Hat OpenShift Dev Spaces (RHOSDS) 3.25
- registry.redhat.io/devspaces/dashboard-rhel9@sha256:d17a2f913e7cef538d6537d0ad32e257e2d51c871fc66183ea291024e8e2afae_s390x as a component of Red Hat OpenShift Dev Spaces (RHOSDS) 3.25
- registry.redhat.io/devspaces/devspaces-operator-bundle@sha256:74b83b79cba88af0545e7fb52dd70df2c1b96cf23b8963517fc779fbfe3e9aac_amd64 as a component of Red Hat OpenShift Dev Spaces (RHOSDS) 3.25
- registry.redhat.io/devspaces/devspaces-rhel9-operator@sha256:46948834924666487d7f47ac11bed7655e936fdb7071ee32d1ae3b1bb1a69aa4_arm64 as a component of Red Hat OpenShift Dev Spaces (RHOSDS) 3.25
- registry.redhat.io/devspaces/devspaces-rhel9-operator@sha256:690264c2631bd5a2341b37c1d3099a84e9bfb5eb2afab2937c0453a2475d0111_ppc64le as a component of Red Hat OpenShift Dev Spaces (RHOSDS) 3.25
- registry.redhat.io/devspaces/devspaces-rhel9-operator@sha256:a4417f71e76b15d9c4f1c4657b2e5f2bb3979d498b362b42d9b207e37bf505d5_amd64 as a component of Red Hat OpenShift Dev Spaces (RHOSDS) 3.25
- registry.redhat.io/devspaces/devspaces-rhel9-operator@sha256:c7871f233d3908f052954b132aa6c7b57c500e41899f02ac023098e2283380c5_s390x as a component of Red Hat OpenShift Dev Spaces (RHOSDS) 3.25
- registry.redhat.io/devspaces/imagepuller-rhel9@sha256:70d4bfd4a877934fbdded33e39c349b3554bc371492ee2696260916b0119efcf_s390x as a component of Red Hat OpenShift Dev Spaces (RHOSDS) 3.25
- registry.redhat.io/devspaces/imagepuller-rhel9@sha256:859b5a54204008d575e774ca4794c346c0195750b5617ae56dccaf3dfa3d3f1b_ppc64le as a component of Red Hat OpenShift Dev Spaces (RHOSDS) 3.25
- registry.redhat.io/devspaces/imagepuller-rhel9@sha256:bc65597fade1fd7de78ab27d9b0ba1bf5317b56949a9277e0af4b32db1aaee48_amd64 as a component of Red Hat OpenShift Dev Spaces (RHOSDS) 3.25
- registry.redhat.io/devspaces/imagepuller-rhel9@sha256:cfa0ae37ba69921586906f410956f9cd7d4a27652a544d3363c7d2dc92603286_arm64 as a component of Red Hat OpenShift Dev Spaces (RHOSDS) 3.25
- registry.redhat.io/devspaces/jetbrains-ide-rhel9@sha256:29fa5d30eafda6658cf2c4a655e82e075b5708ddc1ff1b6d27c082f96c33a95d_amd64 as a component of Red Hat OpenShift Dev Spaces (RHOSDS) 3.25
- registry.redhat.io/devspaces/jetbrains-ide-rhel9@sha256:56bed332699e952d3b4f4672420c379fa32954e77bb24aa3fec51823a0473703_s390x as a component of Red Hat OpenShift Dev Spaces (RHOSDS) 3.25
- registry.redhat.io/devspaces/jetbrains-ide-rhel9@sha256:8714c6e69cdc81f39c44a4d17dda5a4574e104eafeb6d3deb5f29b879e5f0f99_ppc64le as a component of Red Hat OpenShift Dev Spaces (RHOSDS) 3.25
- registry.redhat.io/devspaces/jetbrains-ide-rhel9@sha256:94a3bd9690ce19b7dcab8784e9edaf39a52085d84561659b5ea2e955d375f37e_arm64 as a component of Red Hat OpenShift Dev Spaces (RHOSDS) 3.25
- +32 more not shown
✅ Remediation
Before applying this update, make sure all previously released errata relevant to your system have been applied. For details on how to apply this update, refer to: https://access.redhat.com/articles/11258 Workaround: Mitigation for this issue is either not available or the currently available options don't meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability. To reduced the risk, by disabling or strictly limiting the use of HTTP PUT requests to trusted, authenticated users only. Additionally, administrators should review and adjust URL rewrite rules to ensure they do not manipulate request paths in ways that could expose protected directories such as /WEB-INF/ or /META-INF/. Implementing strict access controls and monitoring for unexpected rewrite or upload behavior can further minimize potential exploitation. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.
🔗 References (11)
- selfhttps://access.redhat.com/errata/RHSA-2025:23225
- externalhttps://access.redhat.com/documentation/en-us/red_hat_openshift_dev_spaces/3.25/html/administration_guide/installing-devspaces
- externalhttps://access.redhat.com/security/cve/CVE-2024-4067
- externalhttps://access.redhat.com/security/cve/CVE-2025-55247
- externalhttps://access.redhat.com/security/cve/CVE-2025-55248
- externalhttps://access.redhat.com/security/cve/CVE-2025-55315
- externalhttps://access.redhat.com/security/cve/CVE-2025-55752
- externalhttps://access.redhat.com/security/cve/CVE-2025-61927
- externalhttps://access.redhat.com/security/cve/CVE-2025-66516
- externalhttps://access.redhat.com/security/updates/classification/
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2025/rhsa-2025_23225.json