RHSA-2025:3374HighCVSS 9.1

Red Hat Security Advisory: Red Hat Developer Hub 1.5.1 release.

Published
March 27, 2025
Last Modified
May 29, 2026

🔗 CVE IDs covered (11)

📋 Description

CVE-2024-45338 — golang.org/x/net/html: Non-linear parsing of case-insensitive content in golang.org/x/net/html CVE-2024-47068 — rollup: DOM Clobbering Gadget found in rollup bundled scripts that leads to XSS CVE-2024-52798 — path-to-regexp: path-to-regexp Unpatched path-to-regexp ReDoS in 0.1.x CVE-2024-55565 — nanoid: nanoid mishandles non-integer values CVE-2024-56201 — jinja2: Jinja has a sandbox breakout through malicious filenames CVE-2024-56326 — jinja2: Jinja has a sandbox breakout through indirect reference to format method CVE-2024-56334 — systeminformation: Command injection vulnerability in getWindowsIEEE8021x (SSID) function in systeminformation CVE-2025-22150 — undici: Undici Uses Insufficiently Random Values CVE-2025-27516 — jinja2: Jinja sandbox breakout through attr filter selecting format method CVE-2025-29774 — xml-crypto: xml-crypto Vulnerable to XML Signature Verification Bypass via Multiple SignedInfo References CVE-2025-29775 — xml-crypto: xml-crypto Vulnerable to XML Signature Verification Bypass via DigestValue Comment

🔗 References (17)