VDB
RHBA-2024%3A9054
RHBA-2024%3A9054
PUBLISHED
CVSS 7.5 HIGH
A flaw was found in the http-proxy-middleware package. Affected versions of this package are vulnerable to denial of service (DoS) due to an UnhandledPromiseRejection error thrown by micromatch. This flaw allows an attacker to kill the Node.js process and crash the server by requesting certain paths.
Risk Scores
CVSS 3.1
7.5
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Red Hat | rhdh/rhdh-rhel9-operator@sha256:8d3e75e17444a5b5b8ffa103b7c880132b2e814245d438363f5434d5d4be1167_amd64 as a component of Red Hat Developer Hub 1.3 for RHEL 9 | * |
| Red Hat | rhdh/rhdh-rhel9-operator@sha256:8d3e75e17444a5b5b8ffa103b7c880132b2e814245d438363f5434d5d4be1167_amd64 as a component of Red Hat Developer Hub 1.3 for RHEL 9 | rhdh/rhdh-rhel9-operator@sha256:8d3e75e17444a5b5b8ffa103b7c880132b2e814245d438363f5434d5d4be1167_amd64 |
| Red Hat | rhdh/rhdh-hub-rhel9@sha256:9bf03585d9a90ad7ba0dd56e9210dbe099be187e9ada06b2a2ca754cefa89314_amd64 as a component of Red Hat Developer Hub 1.3 for RHEL 9 | rhdh/rhdh-hub-rhel9@sha256:9bf03585d9a90ad7ba0dd56e9210dbe099be187e9ada06b2a2ca754cefa89314_amd64 |
| Red Hat | rhdh/rhdh-operator-bundle@sha256:aa2551561078f59c2ac06905bbe51601a438bd8534c5240657964d6e3b685295_amd64 as a component of Red Hat Developer Hub 1.3 for RHEL 9 | * |
| Red Hat | rhdh/rhdh-operator-bundle@sha256:aa2551561078f59c2ac06905bbe51601a438bd8534c5240657964d6e3b685295_amd64 as a component of Red Hat Developer Hub 1.3 for RHEL 9 | rhdh/rhdh-operator-bundle@sha256:aa2551561078f59c2ac06905bbe51601a438bd8534c5240657964d6e3b685295_amd64 |
| Red Hat | rhdh/rhdh-hub-rhel9@sha256:9bf03585d9a90ad7ba0dd56e9210dbe099be187e9ada06b2a2ca754cefa89314_amd64 as a component of Red Hat Developer Hub 1.3 for RHEL 9 | rhdh/rhdh-hub-rhel9@sha256:9bf03585d9a90ad7ba0dd56e9210dbe099be187e9ada06b2a2ca754cefa89314_amd64 |
Timeline
- Nov 11, 2024 CVE Published
- Apr 25, 2026 Security Advisory
- Apr 25, 2026 Security Advisory
- Apr 25, 2026 Security Advisory
- Apr 25, 2026 Security Advisory
- Apr 30, 2026 CVE Updated
References
- https://access.redhat.com/errata/RHBA-2024:9054 advisory
- https://docs.redhat.com/en/documentation/red_hat_developer_hub/1.3 advisory
- https://issues.redhat.com/browse/RHIDP-4343 advisory
- https://issues.redhat.com/browse/RHIDP-4344 advisory
- https://security.access.redhat.com/data/csaf/v2/advisories/2024/rhba-2024_9054.json advisory
- https://access.redhat.com/security/cve/CVE-2024-21536 advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2319884 issue
- https://www.cve.org/CVERecord?id=CVE-2024-21536 advisory
- https://nvd.nist.gov/vuln/detail/CVE-2024-21536 advisory
- https://gist.github.com/mhassan1/28be67266d82a53708ed59ce5dc3c94a advisory
- https://github.com/chimurai/http-proxy-middleware/commit/0b4274e8cc9e9a2c5a06f35fbf456ccfcebc55a5 advisory
- https://github.com/chimurai/http-proxy-middleware/commit/788b21e4aff38332d6319557d4a5b1b13b1f9a22 advisory
- https://security.snyk.io/vuln/SNYK-JS-HTTPPROXYMIDDLEWARE-8229906 advisory
- https://access.redhat.com/security/cve/CVE-2024-37890 advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2292777 issue
- https://www.cve.org/CVERecord?id=CVE-2024-37890 advisory
- https://nvd.nist.gov/vuln/detail/CVE-2024-37890 advisory
- https://github.com/websockets/ws/security/advisories/GHSA-3h5v-q93c-6h6q advisory
- https://access.redhat.com/security/cve/CVE-2024-45590 advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2311171 issue
…and 4 more