RHSA-2025:8540HighCVSS 7.5

Red Hat Security Advisory: Red Hat Developer Hub 1.5.2 release.

Published
June 4, 2025
Last Modified
August 9, 2026

🔗 CVE IDs covered (1)

📋 Description

CVE-2024-12905 — tar-fs: link following and path traversal via maliciously crafted tar file

🎯 Affected products4

  • Red Hat Developer Hub 1.5
  • registry.redhat.io/rhdh/rhdh-hub-rhel9@sha256:e76a91d43f5fb482b19a42bf2cfc30e183b1331f6db600855600b5a917c889b3_amd64 as a component of Red Hat Developer Hub 1.5
  • registry.redhat.io/rhdh/rhdh-operator-bundle@sha256:13e82b4fccc423d0d68550b084cd37a394fdcdb7313b99e142c1570ccff07d91_amd64 as a component of Red Hat Developer Hub 1.5
  • registry.redhat.io/rhdh/rhdh-rhel9-operator@sha256:6aeb54054d5bd7a122ab1742b2fcfc47e1227e1d7614907ac84cd202aaecfaa5_amd64 as a component of Red Hat Developer Hub 1.5

✅ Remediation

For more about Red Hat Developer Hub, see References links

🔗 References (7)