Login
Newsletter
Werbung

Sicherheit: Mehrere Probleme in Red Hat Developer Hub
Aktuelle Meldungen Distributionen
Name: Mehrere Probleme in Red Hat Developer Hub
ID: RHSA-2025:3374
Distribution: Red Hat
Plattformen: Red Hat Developer Hub (RHDH) 1.5
Datum: Fr, 28. März 2025, 06:33
Referenzen: https://access.redhat.com/errata/RHSA-2025:3374
https://access.redhat.com/security/cve/CVE-2024-56326
https://access.redhat.com/security/cve/CVE-2025-22150
https://access.redhat.com/security/cve/CVE-2024-47068
https://access.redhat.com/security/cve/CVE-2024-55565
https://docs.redhat.com/en/documentation/red_hat_developer_hub
https://catalog.redhat.com/search?gs&searchType=containers&q=rhdh
https://access.redhat.com/security/cve/CVE-2024-56334
https://access.redhat.com/security/cve/CVE-2024-52798
https://access.redhat.com/security/cve/CVE-2025-29775
https://access.redhat.com/security/cve/CVE-2024-45338
https://developers.redhat.com/rhdh/overview
https://access.redhat.com/security/cve/CVE-2024-56201
Applikationen: Red Hat Developer Hub

Originalnachricht

Red Hat Developer Hub 1.5.1 has been released.

Red Hat Developer Hub (RHDH) is Red Hat's enterprise-grade, self-managed,
customizable developer portal based on Backstage.io. RHDH is supported on OpenShift and other major Kubernetes clusters (AKS, EKS, GKE). The core features of RHDH include a single pane of glass, a centralized software catalog, self-service via golden path templates, and Tech Docs. RHDH is extensible by plugins.

This content is licensed under the Creative Commons Attribution 4.0 International License (https://creativecommons.org/licenses/by/4.0/). If you distribute this content, or a modified version of it, you must provide attribution to Red Hat Inc. and provide a link to the original.

CVE-2024-45338: Allocation of Resources Without Limits or Throttling (CWE-770)
CVE-2024-47068: Improper Neutralization of Input During Web Page Generation
('Cross-site Scripting') (CWE-79)
CVE-2024-52798: Inefficient Regular Expression Complexity (CWE-1333)
CVE-2024-55565: Loop with Unreachable Exit Condition ('Infinite Loop')
(CWE-835)
CVE-2024-56201: Improper Neutralization of Escape, Meta, or Control Sequences
(CWE-150)
CVE-2024-56326: Protection Mechanism Failure (CWE-693)
CVE-2024-56334: Improper Control of Generation of Code ('Code
Injection') (CWE-94)
CVE-2025-22150: Use of Insufficiently Random Values (CWE-330)
CVE-2025-29775: Improper Verification of Cryptographic Signature (CWE-347)
Pro-Linux
Pro-Linux @Facebook
Neue Nachrichten
Werbung