Red Hat Bug Fix Advisory: Red Hat Developer Hub 1.4.0 release.
🔗 CVE IDs covered (8)
📋 Description
CVE-2024-21536 — http-proxy-middleware: Denial of Service CVE-2024-21538 — cross-spawn: regular expression denial of service CVE-2024-45296 — path-to-regexp: Backtracking regular expressions cause ReDoS CVE-2024-45590 — body-parser: Denial of Service Vulnerability in body-parser CVE-2024-45815 — plugin-catalog-backend: prototype pollution vulnerability CVE-2024-45816 — plugin-techdocs-backend: storage bucket directory traversal in TechDocs CVE-2024-46976 — plugin-techdocs-backend: circumvention of XSS protection in TechDocs CVE-2024-47762 — backstage/plugin-app-backend: Unexpected visibility of environment variable configurations in @backstage/plugin-app-backend
🎯 Affected products4
- RHDH 1.4
- registry.redhat.io/rhdh/rhdh-hub-rhel9@sha256:48edcf6f736e17f33d3630ce2fddc19e95316b7824a7af24e9f0df48ac4f4fe3_amd64 as a component of RHDH 1.4
- registry.redhat.io/rhdh/rhdh-operator-bundle@sha256:2981d2470951ea1e26eb968aefc39ab48ab7d9634a520cf2bbd8c5fef313db15_amd64 as a component of RHDH 1.4
- registry.redhat.io/rhdh/rhdh-rhel9-operator@sha256:448fba0f5f87dc6508b96503fbb794b5b67ed4dea3c95f42d5accdfe1c77e721_amd64 as a component of RHDH 1.4
✅ Remediation
For more about Red Hat Developer Hub, see References links Workaround: Red Hat Product Security does not have any mitigation recommendations at this time. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability. Workaround: Mitigation for this issue is either not available or the currently available options don't meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability. Workaround: Avoid supplying secrets using the APP_CONFIG_* configuration pattern. Consider alternative methods such as the environment variable substitution. See this link for more information about environment variable substitution: https://backstage.io/docs/conf/writing/#environment-variable-substitution
🔗 References (13)
- selfhttps://access.redhat.com/errata/RHBA-2024:11265
- externalhttps://developers.redhat.com/rhdh/overview
- externalhttps://docs.redhat.com/en/documentation/red_hat_developer_hub
- externalhttps://catalog.redhat.com/search?gs&searchType=containers&q=rhdh
- externalhttps://access.redhat.com/security/cve/CVE-2024-21536
- externalhttps://access.redhat.com/security/cve/CVE-2024-21538
- externalhttps://access.redhat.com/security/cve/CVE-2024-45296
- externalhttps://access.redhat.com/security/cve/CVE-2024-45590
- externalhttps://access.redhat.com/security/cve/CVE-2024-45815
- externalhttps://access.redhat.com/security/cve/CVE-2024-45816
- externalhttps://access.redhat.com/security/cve/CVE-2024-46976
- externalhttps://access.redhat.com/security/cve/CVE-2024-47762
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2024/rhba-2024_11265.json