Red Hat Security Advisory: Red Hat Developer Hub 1.6.2 release.
🔗 CVE IDs covered (4)
📋 Description
CVE-2025-32996 — http-proxy-middleware: Always-Incorrect Control Flow Implementation in http-proxy-middleware CVE-2025-32997 — http-proxy-middleware: Improper Check for Unusual or Exceptional Conditions in http-proxy-middleware CVE-2025-47273 — setuptools: Path Traversal Vulnerability in setuptools PackageIndex CVE-2025-48387 — tar-fs: tar-fs has issue where extract can write outside the specified dir with a specific tarball
🎯 Affected products4
- RHDH 1.6
- registry.redhat.io/rhdh/rhdh-hub-rhel9@sha256:79618b38d6f02457954b227d538e238fdebbb72a220af5bd6be3cfab3ad0f262_amd64 as a component of RHDH 1.6
- registry.redhat.io/rhdh/rhdh-operator-bundle@sha256:c99f378315b703b586196ea3978e3858e2c73d4b16d761700efafc9a82e618d9_amd64 as a component of RHDH 1.6
- registry.redhat.io/rhdh/rhdh-rhel9-operator@sha256:fc721db8c90951b6a2255fd893ec0094b47a2c736ce66b41c96d7a4fdae43feb_amd64 as a component of RHDH 1.6
✅ Remediation
For more about Red Hat Developer Hub, see References links Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability. Workaround: Mitigation is either unavailable or does not meet Red Hat Product Security standards for usability, deployment, applicability, or stability.
🔗 References (12)
- selfhttps://access.redhat.com/errata/RHSA-2025:9966
- externalhttps://access.redhat.com/security/cve/CVE-2025-32996
- externalhttps://access.redhat.com/security/cve/CVE-2025-32997
- externalhttps://access.redhat.com/security/cve/CVE-2025-47273
- externalhttps://access.redhat.com/security/cve/CVE-2025-48387
- externalhttps://access.redhat.com/security/updates/classification/
- externalhttps://catalog.redhat.com/search?gs&searchType=containers&q=rhdh
- externalhttps://developers.redhat.com/rhdh/overview
- externalhttps://docs.redhat.com/en/documentation/red_hat_developer_hub
- externalhttps://issues.redhat.com/browse/RHIDP-7725
- externalhttps://issues.redhat.com/browse/RHIDP-7726
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2025/rhsa-2025_9966.json