RHSA-2025:3374HighCVSS 9.1

Red Hat Security Advisory: Red Hat Developer Hub 1.5.1 release.

Published
March 27, 2025
Last Modified
August 19, 2026

🔗 CVE IDs covered (11)

📋 Description

CVE-2024-45338 — golang.org/x/net/html: Non-linear parsing of case-insensitive content in golang.org/x/net/html CVE-2024-47068 — rollup: DOM Clobbering Gadget found in rollup bundled scripts that leads to XSS CVE-2024-52798 — path-to-regexp: path-to-regexp Unpatched path-to-regexp ReDoS in 0.1.x CVE-2024-55565 — nanoid: nanoid mishandles non-integer values CVE-2024-56201 — jinja2: Jinja has a sandbox breakout through malicious filenames CVE-2024-56326 — jinja2: Jinja has a sandbox breakout through indirect reference to format method CVE-2024-56334 — systeminformation: Command injection vulnerability in getWindowsIEEE8021x (SSID) function in systeminformation CVE-2025-22150 — undici: Undici Uses Insufficiently Random Values CVE-2025-27516 — jinja2: Jinja sandbox breakout through attr filter selecting format method CVE-2025-29774 — xml-crypto: xml-crypto Vulnerable to XML Signature Verification Bypass via Multiple SignedInfo References CVE-2025-29775 — xml-crypto: xml-crypto Vulnerable to XML Signature Verification Bypass via DigestValue Comment

🎯 Affected products4

  • Red Hat Developer Hub 1.5
  • registry.redhat.io/rhdh/rhdh-hub-rhel9@sha256:56bfbb2328f42e91d0462e142f3434e5d771737defbc07d8a21dbdf50e468665_amd64 as a component of Red Hat Developer Hub 1.5
  • registry.redhat.io/rhdh/rhdh-operator-bundle@sha256:c870eb3d17807a9d04011df5244ea39db66af76aefd0af68244c95ed8322d8b5_amd64 as a component of Red Hat Developer Hub 1.5
  • registry.redhat.io/rhdh/rhdh-rhel9-operator@sha256:fb4e2008ce87732246bebff004496125f7562b10a60f01eda658e4266d9d0158_amd64 as a component of Red Hat Developer Hub 1.5

✅ Remediation

For more about Red Hat Developer Hub, see References links Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability. Workaround: Avoid using two parameters within a single path segment when the separator is not, for example, /:a-:b. Alternatively, you can define the regex used for both parameters and ensure they do not overlap to allow backtracking. Workaround: To mitigate this vulnerabilty restrict user-controlled template filenames, ensuring they follow a predefined templates. Workaround: Mitigation for this issue is either not available or the currently available options don't meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.

🔗 References (17)