RHSA-2025:3595HighCVSS 9.1

Red Hat Security Advisory: Red Hat Developer Hub 1.4.3 release.

Published
April 3, 2025
Last Modified
September 4, 2026

🔗 CVE IDs covered (3)

📋 Description

CVE-2025-27516 — jinja2: Jinja sandbox breakout through attr filter selecting format method CVE-2025-29774 — xml-crypto: xml-crypto Vulnerable to XML Signature Verification Bypass via Multiple SignedInfo References CVE-2025-29775 — xml-crypto: xml-crypto Vulnerable to XML Signature Verification Bypass via DigestValue Comment

🎯 Affected products4

  • RHDH 1.4
  • registry.redhat.io/rhdh/rhdh-hub-rhel9@sha256:577bd1595325229ba368ad2ece71faf31aec93c088e76c4bba507bf67e41753a_amd64 as a component of RHDH 1.4
  • registry.redhat.io/rhdh/rhdh-operator-bundle@sha256:093c6a66d4faa1d980e4319a048db8b2869eba8f13f40f02615d6696257e6719_amd64 as a component of RHDH 1.4
  • registry.redhat.io/rhdh/rhdh-rhel9-operator@sha256:390855c371faf70fcb11c47177ca9a8d360ba633732c2c8018f9dbc25c5d5047_amd64 as a component of RHDH 1.4

✅ Remediation

For more about Red Hat Developer Hub, see References links Workaround: Mitigation for this issue is either not available or the currently available options don't meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.

🔗 References (9)