Red Hat Security Advisory: A Subscription Management tool for finding and reporting Red Hat product usage
🔗 CVE IDs covered (12)
📋 Description
CVE-2023-4752 — vim: use-after-free in function ins_compl_get_exp in vim/vim CVE-2024-8176 — libexpat: expat: Improper Restriction of XML Entity Expansion Depth in libexpat CVE-2024-12087 — rsync: Path traversal vulnerability in rsync CVE-2024-12088 — rsync: --safe-links option bypass leads to path traversal CVE-2024-12133 — libtasn1: Inefficient DER Decoding in libtasn1 Leading to Potential Remote DoS CVE-2024-12243 — gnutls: GnuTLS Impacted by Inefficient DER Decoding in libtasn1 Leading to Remote DoS CVE-2024-12747 — rsync: Race Condition in rsync Handling Symbolic Links CVE-2024-35195 — requests: subsequent requests to the same host ignore cert verification CVE-2024-52005 — git: The sideband payload is passed unfiltered to the terminal in git CVE-2025-0938 — python: cpython: URL parser allowed square brackets in domain names CVE-2025-24528 — krb5: overflow when calculating ulog block size CVE-2025-26465 — openssh: Machine-in-the-middle attack if VerifyHostKeyDNS is enabled
🎯 Affected products5
- Red Hat Discovery 1.14
- registry.redhat.io/discovery/discovery-server-rhel9@sha256:ad1045aa0de937c3a6969ec377f7bfeda9a44ee434a954e8245e9840316ffc1c_arm64 as a component of Red Hat Discovery 1.14
- registry.redhat.io/discovery/discovery-server-rhel9@sha256:f33991d766b618a128fb99fbe4f9b61c5004f7c6aa73b2b38e28d59e56c64d63_amd64 as a component of Red Hat Discovery 1.14
- registry.redhat.io/discovery/discovery-ui-rhel9@sha256:492e412759cf0eedfa5b557f7b0865f8864f84d0ed75e11dc8d7a840837d9644_amd64 as a component of Red Hat Discovery 1.14
- registry.redhat.io/discovery/discovery-ui-rhel9@sha256:c960fa13577db72b52765d6941688f431f61fe38adb717b2d8bb6569e241bc5e_arm64 as a component of Red Hat Discovery 1.14
✅ Remediation
The containers required to run Discovery can be installed through discovery-installer RPM. See the official documentation for more details. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.
🔗 References (16)
- selfhttps://access.redhat.com/errata/RHSA-2025:8385
- externalhttps://access.redhat.com/security/cve/CVE-2023-4752
- externalhttps://access.redhat.com/security/cve/CVE-2024-12087
- externalhttps://access.redhat.com/security/cve/CVE-2024-12088
- externalhttps://access.redhat.com/security/cve/CVE-2024-12133
- externalhttps://access.redhat.com/security/cve/CVE-2024-12243
- externalhttps://access.redhat.com/security/cve/CVE-2024-12747
- externalhttps://access.redhat.com/security/cve/CVE-2024-35195
- externalhttps://access.redhat.com/security/cve/CVE-2024-52005
- externalhttps://access.redhat.com/security/cve/CVE-2024-8176
- externalhttps://access.redhat.com/security/cve/CVE-2025-0938
- externalhttps://access.redhat.com/security/cve/CVE-2025-24528
- externalhttps://access.redhat.com/security/cve/CVE-2025-26465
- externalhttps://access.redhat.com/security/updates/classification/
- externalhttps://docs.redhat.com/en/documentation/subscription_central/1-latest/#Discovery
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2025/rhsa-2025_8385.json