RHSA-2025:2754HighCVSS 8.8

Red Hat Security Advisory: Red Hat OpenShift Builds 1.3

Published
March 13, 2025
Last Modified
August 17, 2026

🔗 CVE IDs covered (2)

📋 Description

CVE-2024-12797 — openssl: RFC7250 handshakes with unauthenticated servers don't abort as expected CVE-2025-1244 — emacs: Shell Injection Vulnerability in GNU Emacs via Custom "man" URI Scheme

🎯 Affected products41

  • Builds for Red Hat OpenShift 1.3.2
  • registry.redhat.io/openshift-builds/openshift-builds-controller-rhel9@sha256:02d0ae03cf0122360b8dac54467295bfd4a97ea32471bc9b524bca437eaf61ee_s390x as a component of Builds for Red Hat OpenShift 1.3.2
  • registry.redhat.io/openshift-builds/openshift-builds-controller-rhel9@sha256:2a298d279e1082cf88e83f9d41216c5f120c506ee01f0393e5dc8f1fad9ced58_ppc64le as a component of Builds for Red Hat OpenShift 1.3.2
  • registry.redhat.io/openshift-builds/openshift-builds-controller-rhel9@sha256:48b003c2670a6aa552de9586b055dd23fba2b28c04bbdff088b90bc68126d0ff_arm64 as a component of Builds for Red Hat OpenShift 1.3.2
  • registry.redhat.io/openshift-builds/openshift-builds-controller-rhel9@sha256:be45a37a6a4b5685af69e426ffae4601b2bf087336bd30b3667fbc6da0014ac4_amd64 as a component of Builds for Red Hat OpenShift 1.3.2
  • registry.redhat.io/openshift-builds/openshift-builds-git-cloner-rhel9@sha256:02dfa9ff3833810645246f3af3ef89c2ea6794b61f3cdfe0929596ebf5bf042f_amd64 as a component of Builds for Red Hat OpenShift 1.3.2
  • registry.redhat.io/openshift-builds/openshift-builds-git-cloner-rhel9@sha256:73407faadc9e5a34e9baf2ff089805b49ec503972a5d02111857ea6e79780877_arm64 as a component of Builds for Red Hat OpenShift 1.3.2
  • registry.redhat.io/openshift-builds/openshift-builds-git-cloner-rhel9@sha256:8bb5f5d121a135ddd3c3038167b2bed668efe4f2d2c69a6e7e1bb5671c9e3043_ppc64le as a component of Builds for Red Hat OpenShift 1.3.2
  • registry.redhat.io/openshift-builds/openshift-builds-git-cloner-rhel9@sha256:dc839b2217a61a4ac07cefecc0b5a0cf8c907d7b7114ca15b5ca368f57de921a_s390x as a component of Builds for Red Hat OpenShift 1.3.2
  • registry.redhat.io/openshift-builds/openshift-builds-image-bundler-rhel9@sha256:56b7282d138904aa9b1ff732e356ddb6b3bdec93f089313f733bf50f706191a9_arm64 as a component of Builds for Red Hat OpenShift 1.3.2
  • registry.redhat.io/openshift-builds/openshift-builds-image-bundler-rhel9@sha256:628167b3348b5baa7e83b8c70998dd57618153d53883018fa58f3720093b46b3_amd64 as a component of Builds for Red Hat OpenShift 1.3.2
  • registry.redhat.io/openshift-builds/openshift-builds-image-bundler-rhel9@sha256:6bbac2dc3fad147fdaaa493c9d95a0e9f95ae62a0d14ebbb70dafb242d76424c_s390x as a component of Builds for Red Hat OpenShift 1.3.2
  • registry.redhat.io/openshift-builds/openshift-builds-image-bundler-rhel9@sha256:f95f0efbe8acc857cda9b692ad85e7ee0d7d9bee7709c75a82823c249141d88a_ppc64le as a component of Builds for Red Hat OpenShift 1.3.2
  • registry.redhat.io/openshift-builds/openshift-builds-image-processing-rhel9@sha256:5de6938bd11e92c9da98ea267697f9ef6b0ceced1d13a75bce80b138641d3d16_amd64 as a component of Builds for Red Hat OpenShift 1.3.2
  • registry.redhat.io/openshift-builds/openshift-builds-image-processing-rhel9@sha256:748a1949915fe211bd9ee4af457dd228f189948e3d8a5a8a52255f7a8ee98931_arm64 as a component of Builds for Red Hat OpenShift 1.3.2
  • registry.redhat.io/openshift-builds/openshift-builds-image-processing-rhel9@sha256:8908e3b99a75e5e0936426f52c0e71c76fdc44c1a229298bc7b0fec53ea372ac_ppc64le as a component of Builds for Red Hat OpenShift 1.3.2
  • registry.redhat.io/openshift-builds/openshift-builds-image-processing-rhel9@sha256:eb70675111930268da24ba834045532d133a399774cb24244b36ea11e52dec21_s390x as a component of Builds for Red Hat OpenShift 1.3.2
  • registry.redhat.io/openshift-builds/openshift-builds-operator-bundle@sha256:7a6ef43322827fe9e35d1c907eb02fd05a7b5ad370d85c93a32e0454bb7aa322_ppc64le as a component of Builds for Red Hat OpenShift 1.3.2
  • registry.redhat.io/openshift-builds/openshift-builds-operator-bundle@sha256:9aac117b49257558dc21cf1a2b3fcf7987672a9b21a98745810cce142f2c5170_arm64 as a component of Builds for Red Hat OpenShift 1.3.2
  • registry.redhat.io/openshift-builds/openshift-builds-operator-bundle@sha256:a4e5307c4a4cbceef29ce74064a6729ab7e7dc88ad2afe158c0534978aefdc46_s390x as a component of Builds for Red Hat OpenShift 1.3.2
  • registry.redhat.io/openshift-builds/openshift-builds-operator-bundle@sha256:bcc64657fb3bb868aba32b362c8122eaaf45a4db82c351098a26ea80980e0c1c_amd64 as a component of Builds for Red Hat OpenShift 1.3.2
  • registry.redhat.io/openshift-builds/openshift-builds-rhel9-operator@sha256:30a93c9087a20a33051ca970a0862cfa5e0f447b58a8f0c980b876825a544c85_s390x as a component of Builds for Red Hat OpenShift 1.3.2
  • registry.redhat.io/openshift-builds/openshift-builds-rhel9-operator@sha256:8f946b8a04e4a14195ad6bf54f84b82aacec8dd5ec8167f7051751acba388369_arm64 as a component of Builds for Red Hat OpenShift 1.3.2
  • registry.redhat.io/openshift-builds/openshift-builds-rhel9-operator@sha256:ac054977db4a4c6d404582cda6b83ab56ddda02a08394547536c31cd2d3dce87_amd64 as a component of Builds for Red Hat OpenShift 1.3.2
  • registry.redhat.io/openshift-builds/openshift-builds-rhel9-operator@sha256:e5026b273984bc566d3054496d693694de9885671157f73e892934ceb1408a38_ppc64le as a component of Builds for Red Hat OpenShift 1.3.2
  • registry.redhat.io/openshift-builds/openshift-builds-shared-resource-rhel9@sha256:06780cf9d827b4e3c111e32d983db02d13e740817a09bcf281d1ffd3c225cdf8_s390x as a component of Builds for Red Hat OpenShift 1.3.2
  • registry.redhat.io/openshift-builds/openshift-builds-shared-resource-rhel9@sha256:80dd2052f12f08d9c7fe07113a7b3e6fa2bbb559bbce6ea828cd826f722eee37_amd64 as a component of Builds for Red Hat OpenShift 1.3.2
  • registry.redhat.io/openshift-builds/openshift-builds-shared-resource-rhel9@sha256:a63d86f558e51e6233b4c5262311602f50c34b16154741f1062a598d67f4c0d7_arm64 as a component of Builds for Red Hat OpenShift 1.3.2
  • registry.redhat.io/openshift-builds/openshift-builds-shared-resource-rhel9@sha256:e72cc7ddc903d23da260255cbf5d674841b8c3c4d9445aea822d6ab33be69500_ppc64le as a component of Builds for Red Hat OpenShift 1.3.2
  • registry.redhat.io/openshift-builds/openshift-builds-shared-resource-webhook-rhel9@sha256:9a178523f8537a5c3e66b320e15370f01d74702f45eca46f3a34c937518f40a0_arm64 as a component of Builds for Red Hat OpenShift 1.3.2
  • +11 more not shown

✅ Remediation

It is recommended that existing users of Red Hat OpenShift Builds 1.2 to 1.3. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability. Workaround: There is no an existing or known mitigation for this issue without disabling part of the Emacs core functionality. However, by avoiding opening or view untrusted files, websites, HTTP URLs or other URI resources with Emacs would reduce or prevent the risk of performing this attack successfully.

🔗 References (5)