RHSA-2025:22404HighCVSS 8.2
Red Hat Security Advisory: Red Hat Developer Hub 1.7.3 release.
🔗 CVE IDs covered (1)
📋 Description
CVE-2025-60542 — TypeORM: SQL Injection via crafted request to repository.save or repository.update
🎯 Affected products4
- Red Hat Developer Hub 1.7
- registry.redhat.io/rhdh/rhdh-hub-rhel9@sha256:bedacfa68d74fce1e9efe3a3fdb18963f4e648d7ab6ccf34b868d62d9f25304a_amd64 as a component of Red Hat Developer Hub 1.7
- registry.redhat.io/rhdh/rhdh-operator-bundle@sha256:54c5cd2a4865a372ba9465908f73928382745e04ad446c97b28adde213d13309_amd64 as a component of Red Hat Developer Hub 1.7
- registry.redhat.io/rhdh/rhdh-rhel9-operator@sha256:f45ee5600c84c3d014c8bfb9a06e3b600acaa74ce8ff4bf12e5124d25cbe5bfe_amd64 as a component of Red Hat Developer Hub 1.7
✅ Remediation
For more about Red Hat Developer Hub, see References links Workaround: Red Hat has investigated whether a possible mitigation exists for this issue, and has not been able to identify a practical example. Please update the affected package as soon as possible.
🔗 References (9)
- selfhttps://access.redhat.com/errata/RHSA-2025:22404
- externalhttps://access.redhat.com/security/cve/CVE-2025-60542
- externalhttps://access.redhat.com/security/updates/classification/
- externalhttps://catalog.redhat.com/search?gs&searchType=containers&q=rhdh
- externalhttps://developers.redhat.com/rhdh/overview
- externalhttps://docs.redhat.com/en/documentation/red_hat_developer_hub
- externalhttps://issues.redhat.com/browse/RHDHPLAN-367
- externalhttps://issues.redhat.com/browse/RHIDP-9741
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2025/rhsa-2025_22404.json