Skip to main content
EPSS 2.5%top 16%

Red Hat Security Advisory: Red Hat OpenShift Builds 1.3

0
High
Published: 03/13/2025 (03/13/2025, 13:23:17 UTC)
Source: GCVE Database
Vendor/Project: Red Hat Product Security
Product: Red Hat

Description

Red Hat OpenShift Builds 1.3

Affected software

Affected versions
>=1.2 <=1.3Red HatBuilds for Red Hat OpenShiftBuilds for Red Hat OpenShift 1.3.2amd64registry.redhat.io/openshift-builds/openshift-builds-controller-rhel9@sha256:be45a37a6a4b5685af69e426ffae4601b2bf087336bd30b3667fbc6da0014ac4_amd64

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 08/16/2026, 18:27:40 UTC

Technical Analysis

This vulnerability (CVE-2024-12797) is due to improper certificate validation in OpenSSL's implementation of RFC7250 Raw Public Key (RPK) authentication. Specifically, when RPK is enabled on both TLS clients and servers, the TLS/DTLS handshake fails to abort if the server's RPK does not match the expected key, even though SSL_VERIFY_PEER verification mode is set. This flaw allows an attacker to perform man-in-the-middle attacks by spoofing the server's identity. The vulnerability was introduced in OpenSSL 3.2, first shipped in RHEL 9.5, and affects Red Hat OpenShift Builds versions 1.2 through 1.3. RPK is disabled by default, so only users who explicitly enable RPK are affected. Ruby packages in RHEL are not affected as they do not expose RPK functions. No official fix is currently available, and mitigation options do not meet Red Hat's criteria for ease of use or applicability. Users are advised to monitor Red Hat advisories for future updates.

Potential Impact

The vulnerability allows an attacker to bypass TLS authentication by exploiting the failure to abort handshakes when the server's raw public key does not match the expected key. This can lead to man-in-the-middle attacks, enabling attackers to intercept or spoof communications that clients believe are secure. Confidentiality and integrity of communications are at high risk. Availability is not impacted. The issue affects only configurations where RPK is explicitly enabled on both client and server sides.

Mitigation Recommendations

Currently, no official fix or patch is available for this vulnerability. Red Hat advises users to upgrade to supported product versions beyond 1.3 when available. Since RPK is disabled by default, users should avoid enabling RPK on TLS clients and servers unless necessary. Clients that explicitly check the verification result via SSL_get_verify_result() and handle failures appropriately are not affected. Users should monitor Red Hat advisories for future patches or updates. No additional mitigations meeting Red Hat's criteria are currently recommended.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Gcve Source
db.gcve.eu
Csaf Category
csaf_security_advisory
Csaf Version
2.0
Publisher
Red Hat Product Security
Advisory Id
RHSA-2025:2754
Cve Count
2
Additional Cves
["CVE-2025-1244"]

Threat ID: 6a1f4e89e29bf47b50083a13

Added to database: 06/02/2026, 21:43:37 UTC

Last enriched: 08/16/2026, 18:27:40 UTC

Last updated: 09/10/2026, 19:24:53 UTC

Views: 295

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses