RHSA-2025:8540HighCVSS 7.5
Red Hat Security Advisory: Red Hat Developer Hub 1.5.2 release.
🔗 CVE IDs covered (1)
📋 Description
CVE-2024-12905 — tar-fs: link following and path traversal via maliciously crafted tar file
🎯 Affected products4
- Red Hat Developer Hub 1.5
- registry.redhat.io/rhdh/rhdh-hub-rhel9@sha256:e76a91d43f5fb482b19a42bf2cfc30e183b1331f6db600855600b5a917c889b3_amd64 as a component of Red Hat Developer Hub 1.5
- registry.redhat.io/rhdh/rhdh-operator-bundle@sha256:13e82b4fccc423d0d68550b084cd37a394fdcdb7313b99e142c1570ccff07d91_amd64 as a component of Red Hat Developer Hub 1.5
- registry.redhat.io/rhdh/rhdh-rhel9-operator@sha256:6aeb54054d5bd7a122ab1742b2fcfc47e1227e1d7614907ac84cd202aaecfaa5_amd64 as a component of Red Hat Developer Hub 1.5
✅ Remediation
For more about Red Hat Developer Hub, see References links
🔗 References (7)
- selfhttps://access.redhat.com/errata/RHSA-2025:8540
- externalhttps://access.redhat.com/security/cve/CVE-2024-12905
- externalhttps://access.redhat.com/security/updates/classification/
- externalhttps://catalog.redhat.com/search?gs&searchType=containers&q=rhdh
- externalhttps://developers.redhat.com/rhdh/overview
- externalhttps://docs.redhat.com/en/documentation/red_hat_developer_hub
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2025/rhsa-2025_8540.json