VDB

RHBA-2024%3A10184

RHBA-2024%3A10184 PUBLISHED CVSS 7.5 HIGH

A flaw was found in browserify-sign node package. This issue may allow a malicious user to execute a signature forgery attack by not correctly checking cryptographic signatures for DSA data, resulting in a jeopardized environment.

Risk Scores

CVSS 3.1
7.5
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

Affected Products

VendorProductVersions
Red Hatrhdh/rhdh-operator-bundle@sha256:808b5e941f390c695cb713b86066ff833537ce7c3e387c2c260f0aecdeae30d6_amd64 as a component of Red Hat Developer Hub 1.2 for RHEL 9rhdh/rhdh-operator-bundle@sha256:808b5e941f390c695cb713b86066ff833537ce7c3e387c2c260f0aecdeae30d6_amd64
Red Hatrhdh/rhdh-hub-rhel9@sha256:f767bbaa49d570a56a56bf0a645dcedd3ffa2708eba0ec15bfad7ff945bb32e0_amd64 as a component of Red Hat Developer Hub 1.2 for RHEL 9rhdh/rhdh-hub-rhel9@sha256:f767bbaa49d570a56a56bf0a645dcedd3ffa2708eba0ec15bfad7ff945bb32e0_amd64
Red Hatrhdh/rhdh-rhel9-operator@sha256:a311b97bd9d865a028653f9dd754b32aabe60ca128c5b97d899b6c81a24000e5_amd64 as a component of Red Hat Developer Hub 1.2 for RHEL 9rhdh/rhdh-rhel9-operator@sha256:a311b97bd9d865a028653f9dd754b32aabe60ca128c5b97d899b6c81a24000e5_amd64
Red Hatrhdh/rhdh-operator-bundle@sha256:808b5e941f390c695cb713b86066ff833537ce7c3e387c2c260f0aecdeae30d6_amd64 as a component of Red Hat Developer Hub 1.2 for RHEL 9rhdh/rhdh-operator-bundle@sha256:808b5e941f390c695cb713b86066ff833537ce7c3e387c2c260f0aecdeae30d6_amd64
Red Hatrhdh/rhdh-rhel9-operator@sha256:a311b97bd9d865a028653f9dd754b32aabe60ca128c5b97d899b6c81a24000e5_amd64 as a component of Red Hat Developer Hub 1.2 for RHEL 9rhdh/rhdh-rhel9-operator@sha256:a311b97bd9d865a028653f9dd754b32aabe60ca128c5b97d899b6c81a24000e5_amd64
Red Hatrhdh/rhdh-hub-rhel9@sha256:f767bbaa49d570a56a56bf0a645dcedd3ffa2708eba0ec15bfad7ff945bb32e0_amd64 as a component of Red Hat Developer Hub 1.2 for RHEL 9rhdh/rhdh-hub-rhel9@sha256:f767bbaa49d570a56a56bf0a645dcedd3ffa2708eba0ec15bfad7ff945bb32e0_amd64

Timeline

  • Nov 21, 2024 CVE Published
  • Apr 25, 2026 Security Advisory
  • Apr 25, 2026 Security Advisory
  • Apr 25, 2026 Security Advisory
  • Apr 30, 2026 CVE Updated
Open in Interactive Console →
$ Console Community · 100/wk Open console ›