Red Hat Security Advisory: Red Hat Developer Hub 1.6.0 release.
🔗 CVE IDs covered (4)
📋 Description
CVE-2024-12905 — tar-fs: link following and path traversal via maliciously crafted tar file CVE-2024-21534 — jsonpath-plus: Remote Code Execution in jsonpath-plus via Improper Input Sanitization CVE-2025-26791 — dompurify: Mutation XSS in DOMPurify Due to Improper Template Literal Handling CVE-2025-29775 — xml-crypto: xml-crypto Vulnerable to XML Signature Verification Bypass via DigestValue Comment
🎯 Affected products4
- RHDH 1.6
- registry.redhat.io/rhdh/rhdh-hub-rhel9@sha256:b6bf7ded5e146f60141840bb2e42e72125c61af0f3d3c3fbf48b35bc670675fe_amd64 as a component of RHDH 1.6
- registry.redhat.io/rhdh/rhdh-operator-bundle@sha256:3da4799b9a79f688ca55ec85d0b3e28348dbc2661e82110aedbf27dfa97f49e1_amd64 as a component of RHDH 1.6
- registry.redhat.io/rhdh/rhdh-rhel9-operator@sha256:8b723ad5171dd98d9f4d551d80fc883ecf6f8bbc8178911bd04dd1590980681f_amd64 as a component of RHDH 1.6
✅ Remediation
For more about Red Hat Developer Hub, see References links Workaround: Red Hat Product Security recommends updating the vulnerable software to the latest version. Workaround: Mitigation for this issue is either not available or the currently available options don't meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.
🔗 References (10)
- selfhttps://access.redhat.com/errata/RHSA-2025:7626
- externalhttps://access.redhat.com/security/cve/CVE-2024-12905
- externalhttps://access.redhat.com/security/cve/CVE-2024-21534
- externalhttps://access.redhat.com/security/cve/CVE-2025-26791
- externalhttps://access.redhat.com/security/cve/CVE-2025-29775
- externalhttps://access.redhat.com/security/updates/classification/
- externalhttps://catalog.redhat.com/search?gs&searchType=containers&q=rhdh
- externalhttps://developers.redhat.com/rhdh/overview
- externalhttps://docs.redhat.com/en/documentation/red_hat_developer_hub
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2025/rhsa-2025_7626.json