VDB
RHBA-2024%3A10184
RHBA-2024%3A10184
PUBLISHED
CVSS 7.5 HIGH
A flaw was found in browserify-sign node package. This issue may allow a malicious user to execute a signature forgery attack by not correctly checking cryptographic signatures for DSA data, resulting in a jeopardized environment.
Risk Scores
CVSS 3.1
7.5
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Red Hat | rhdh/rhdh-operator-bundle@sha256:808b5e941f390c695cb713b86066ff833537ce7c3e387c2c260f0aecdeae30d6_amd64 as a component of Red Hat Developer Hub 1.2 for RHEL 9 | rhdh/rhdh-operator-bundle@sha256:808b5e941f390c695cb713b86066ff833537ce7c3e387c2c260f0aecdeae30d6_amd64 |
| Red Hat | rhdh/rhdh-hub-rhel9@sha256:f767bbaa49d570a56a56bf0a645dcedd3ffa2708eba0ec15bfad7ff945bb32e0_amd64 as a component of Red Hat Developer Hub 1.2 for RHEL 9 | rhdh/rhdh-hub-rhel9@sha256:f767bbaa49d570a56a56bf0a645dcedd3ffa2708eba0ec15bfad7ff945bb32e0_amd64 |
| Red Hat | rhdh/rhdh-rhel9-operator@sha256:a311b97bd9d865a028653f9dd754b32aabe60ca128c5b97d899b6c81a24000e5_amd64 as a component of Red Hat Developer Hub 1.2 for RHEL 9 | rhdh/rhdh-rhel9-operator@sha256:a311b97bd9d865a028653f9dd754b32aabe60ca128c5b97d899b6c81a24000e5_amd64 |
| Red Hat | rhdh/rhdh-operator-bundle@sha256:808b5e941f390c695cb713b86066ff833537ce7c3e387c2c260f0aecdeae30d6_amd64 as a component of Red Hat Developer Hub 1.2 for RHEL 9 | rhdh/rhdh-operator-bundle@sha256:808b5e941f390c695cb713b86066ff833537ce7c3e387c2c260f0aecdeae30d6_amd64 |
| Red Hat | rhdh/rhdh-rhel9-operator@sha256:a311b97bd9d865a028653f9dd754b32aabe60ca128c5b97d899b6c81a24000e5_amd64 as a component of Red Hat Developer Hub 1.2 for RHEL 9 | rhdh/rhdh-rhel9-operator@sha256:a311b97bd9d865a028653f9dd754b32aabe60ca128c5b97d899b6c81a24000e5_amd64 |
| Red Hat | rhdh/rhdh-hub-rhel9@sha256:f767bbaa49d570a56a56bf0a645dcedd3ffa2708eba0ec15bfad7ff945bb32e0_amd64 as a component of Red Hat Developer Hub 1.2 for RHEL 9 | rhdh/rhdh-hub-rhel9@sha256:f767bbaa49d570a56a56bf0a645dcedd3ffa2708eba0ec15bfad7ff945bb32e0_amd64 |
Timeline
- Nov 21, 2024 CVE Published
- Apr 25, 2026 Security Advisory
- Apr 25, 2026 Security Advisory
- Apr 25, 2026 Security Advisory
- Apr 30, 2026 CVE Updated
References
- https://access.redhat.com/errata/RHBA-2024:10184 advisory
- https://docs.redhat.com/en/documentation/red_hat_developer_hub/1.2 advisory
- https://issues.redhat.com/browse/RHIDP-4215 advisory
- https://issues.redhat.com/browse/RHIDP-4217 advisory
- https://issues.redhat.com/browse/RHIDP-4218 advisory
- https://security.access.redhat.com/data/csaf/v2/advisories/2024/rhba-2024_10184.json advisory
- https://access.redhat.com/security/cve/CVE-2023-46234 advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2246470 issue
- https://www.cve.org/CVERecord?id=CVE-2023-46234 advisory
- https://nvd.nist.gov/vuln/detail/CVE-2023-46234 advisory
- https://github.com/browserify/browserify-sign/security/advisories/GHSA-x9w5-v3q2-3rhw advisory
- https://access.redhat.com/security/cve/CVE-2024-43799 advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2311153 issue
- https://www.cve.org/CVERecord?id=CVE-2024-43799 advisory
- https://nvd.nist.gov/vuln/detail/CVE-2024-43799 advisory
- https://github.com/pillarjs/send/commit/ae4f2989491b392ae2ef3b0015a019770ae65d35 advisory
- https://github.com/pillarjs/send/security/advisories/GHSA-m6fv-jmcg-4jfg advisory