Skip to main content
EPSS 4.0%top 10%

Red Hat Security Advisory: RHTAS 1.1.2 - Red Hat Trusted Artifact Signer Release

0
Medium
Published: 04/10/2025 (04/10/2025, 14:20:32 UTC)
Source: GCVE Database
Vendor/Project: Red Hat Product Security
Product: Red Hat

Description

The RHTAS Operator can be used with OpenShift Container Platform 4.14, 4.15, 4.16, 4.17, and 4.18

Affected software

Affected versions
>=4.14 <=4.18Red HatRed Hat Trusted Artifact SignerRed Hat Trusted Artifact Signer 1.1amd64registry.redhat.io/rhtas/rekor-search-ui-rhel9@sha256:571c48ecb2658ce70199c06dc483ea48a16e032a764a6830388ad845f508d981_amd64

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 08/16/2026, 18:18:01 UTC

Technical Analysis

CVE-2024-51479 is an authorization bypass vulnerability found in the Next.js framework component used by the Red Hat Trusted Artifact Signer Operator. The flaw arises from improper sanitization of a query parameter, leading to invalid routing conditions that can bypass path-based middleware authorization checks. This affects self-hosted applications lacking i18n configuration, specifically for pages directly under the root directory. The vulnerability is tracked under CWE-285 (Improper Authorization) and CWE-770. Red Hat's advisory indicates no current fix is available and that mitigation options are either unavailable or unsuitable for widespread deployment. The affected Red Hat Trusted Artifact Signer versions correspond to usage with OpenShift Container Platform 4.14 to 4.18. The vulnerability does not impact applications hosted on Vercel, and no known exploits are reported in the wild.

Potential Impact

An attacker exploiting this vulnerability could bypass authorization controls in affected self-hosted applications, potentially gaining unauthorized access to sensitive data or functionality protected by path-based middleware authorization. The impact is limited to applications missing i18n configuration and only affects certain URL paths. There is no indication of integrity or availability impact beyond the authorization bypass. No known active exploitation has been reported.

Mitigation Recommendations

Currently, no official fix or patch is available from Red Hat for this vulnerability. Red Hat states that available mitigation options do not meet their criteria for ease of use, applicability, or stability. Users should monitor Red Hat advisories for updates. Applications hosted on Vercel are not vulnerable. Organizations should review their use of path-based middleware authorization and consider configuration changes or alternative authorization mechanisms to reduce exposure until a fix is released.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Gcve Source
db.gcve.eu
Csaf Category
csaf_security_advisory
Csaf Version
2.0
Publisher
Red Hat Product Security
Advisory Id
RHSA-2025:3807
Cve Count
2
Additional Cves
["CVE-2024-56332"]

Threat ID: 6a4049d127e9c7971982b908

Added to database: 06/27/2026, 22:08:17 UTC

Last enriched: 08/16/2026, 18:18:01 UTC

Last updated: 09/10/2026, 19:36:48 UTC

Views: 18

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses