Red Hat Security Advisory: Red Hat Developer Hub 1.5.1 release.
🔗 CVE IDs covered (11)
📋 Description
CVE-2024-45338 — golang.org/x/net/html: Non-linear parsing of case-insensitive content in golang.org/x/net/html
CVE-2024-47068 — rollup: DOM Clobbering Gadget found in rollup bundled scripts that leads to XSS
CVE-2024-52798 — path-to-regexp: path-to-regexp Unpatched path-to-regexp ReDoS in 0.1.x
CVE-2024-55565 — nanoid: nanoid mishandles non-integer values
CVE-2024-56201 — jinja2: Jinja has a sandbox breakout through malicious filenames
CVE-2024-56326 — jinja2: Jinja has a sandbox breakout through indirect reference to format method
CVE-2024-56334 — systeminformation: Command injection vulnerability in getWindowsIEEE8021x (SSID) function in systeminformation
CVE-2025-22150 — undici: Undici Uses Insufficiently Random Values
CVE-2025-27516 — jinja2: Jinja sandbox breakout through attr filter selecting format method
CVE-2025-29774 — xml-crypto: xml-crypto Vulnerable to XML Signature Verification Bypass via Multiple SignedInfo References
CVE-2025-29775 — xml-crypto: xml-crypto Vulnerable to XML Signature Verification Bypass via DigestValue Comment
🔗 References (17)
- selfhttps://access.redhat.com/errata/RHSA-2025:3374
- externalhttps://access.redhat.com/security/cve/CVE-2024-45338
- externalhttps://access.redhat.com/security/cve/CVE-2024-47068
- externalhttps://access.redhat.com/security/cve/CVE-2024-52798
- externalhttps://access.redhat.com/security/cve/CVE-2024-55565
- externalhttps://access.redhat.com/security/cve/CVE-2024-56201
- externalhttps://access.redhat.com/security/cve/CVE-2024-56326
- externalhttps://access.redhat.com/security/cve/CVE-2024-56334
- externalhttps://access.redhat.com/security/cve/CVE-2025-22150
- externalhttps://access.redhat.com/security/cve/CVE-2025-29774
- externalhttps://access.redhat.com/security/cve/CVE-2025-29775
- externalhttps://access.redhat.com/security/cve/cve-2025-27516
- externalhttps://access.redhat.com/security/updates/classification/
- externalhttps://catalog.redhat.com/search?gs&searchType=containers&q=rhdh
- externalhttps://developers.redhat.com/rhdh/overview
- externalhttps://docs.redhat.com/en/documentation/red_hat_developer_hub
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2025/rhsa-2025_3374.json