Skip to navigation Skip to main content

Utilities

  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
Red Hat Customer Portal
  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
  • Products

    Top Products

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Products

    Downloads and Containers

    • Downloads
    • Packages
    • Containers

    Top Resources

    • Documentation
    • Product Life Cycles
    • Product Compliance
    • Errata
  • Knowledge

    Red Hat Knowledge Center

    • Knowledgebase Solutions
    • Knowledgebase Articles
    • Customer Portal Labs
    • Errata

    Top Product Docs

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Product Docs

    Training and Certification

    • About
    • Course Index
    • Certification Index
    • Skill Assessment
  • Security

    Red Hat Product Security Center

    • Security Updates
    • Security Advisories
    • Red Hat CVE Database
    • Errata

    References

    • Security Bulletins
    • Severity Ratings
    • Security Data

    Top Resources

    • Security Labs
    • Backporting Policies
    • Security Blog
  • Support

    Red Hat Support

    • Support Cases
    • Troubleshoot
    • Get Support
    • Contact Red Hat Support

    Red Hat Community Support

    • Customer Portal Community
    • Community Discussions
    • Red Hat Accelerator Program

    Top Resources

    • Product Life Cycles
    • Customer Portal Labs
    • Red Hat JBoss Supported Configurations
    • Red Hat Lightspeed
Or troubleshoot an issue.

Select Your Language

  • English
  • Français
  • 한국어
  • 日本語
  • 中文 (中国)

Infrastructure and Management

  • Red Hat Enterprise Linux
  • Red Hat Satellite
  • Red Hat Subscription Management
  • Red Hat Lightspeed
  • Red Hat Ansible Automation Platform

Cloud Computing

  • Red Hat OpenShift
  • Red Hat OpenStack Platform
  • Red Hat OpenShift
  • Red Hat OpenShift AI
  • Red Hat OpenShift Dedicated
  • Red Hat Advanced Cluster Security for Kubernetes
  • Red Hat Advanced Cluster Management for Kubernetes
  • Red Hat Quay
  • Red Hat OpenShift Dev Spaces
  • Red Hat OpenShift Service on AWS

Storage

  • Red Hat Gluster Storage
  • Red Hat Hyperconverged Infrastructure
  • Red Hat Ceph Storage
  • Red Hat OpenShift Data Foundation

Runtimes

  • Red Hat Runtimes
  • Red Hat JBoss Enterprise Application Platform
  • Red Hat Data Grid
  • Red Hat JBoss Web Server
  • Red Hat build of Keycloak
  • Red Hat support for Spring Boot
  • Red Hat build of Node.js
  • Red Hat build of Quarkus

Integration and Automation

  • Red Hat Application Foundations
  • Red Hat Fuse
  • Red Hat AMQ
  • Red Hat 3scale API Management
All Products
Red Hat Product Errata RHSA-2025:2753 - Security Advisory
Issued:
2025-03-13
Updated:
2025-03-13

RHSA-2025:2753 - Security Advisory

  • Overview
  • Updated Images

Synopsis

Moderate: Red Hat OpenShift Dev Spaces 3.19.0 release

Type/Severity

Security Advisory: Moderate

Topic

Red Hat OpenShift Dev Spaces 3.19 has been released.

All containers have been updated to include feature enhancements, bug fixes and CVE fixes.

Following the Red Hat Product Security standards this update is rated as having a security impact of Important. The Common Vulnerability Scoring System (CVSS) base score is available for every fixed CVE in the references section.

Description

Red Hat OpenShift Dev Spaces provides a cloud developer workspace server and a browser-based IDE built for teams and organizations. Dev Spaces runs in OpenShift and is well-suited for container-based development.

The 3.19 release is based on Eclipse Che 7.98 and uses the DevWorkspace engine to provide support for workspaces based on devfile v2.1 and v2.2.

This release includes fixes to the following CVE:
CVE-2025-23207 fixed in devspaces-code

Users still using the v1 standard should migrate as soon as possible.

https://devfile.io/docs/2.2.0/migrating-to-devfile-v2

Dev Spaces releases support the latest two OpenShift 4 EUS releases. Users are expected to update to newer OpenShift releases in order to continue to get Dev Spaces updates.

https://access.redhat.com/support/policy/updates/openshift#devspaces

Solution

Before applying this update, make sure all previously released errata
relevant to your system have been applied.

For details on how to apply this update, refer to:

https://access.redhat.com/articles/11258

Affected Products

  • Red Hat OpenShift Dev Spaces 3 x86_64

Fixes

  • BZ - 2338681 - CVE-2025-23207 katex: \htmlData does not validate attribute names in KaTeX
  • CRW-7972 - DS 3.19.0 Overall Epic

CVEs

  • CVE-2020-11023
  • CVE-2024-12797
  • CVE-2025-23207

References

  • https://access.redhat.com/security/updates/classification/#moderate

ppc64le

devspaces-tech-preview/jetbrains-ide-rhel9@sha256:1d8ea018fe82220a2def92de9f6417b5213ff4341e56ab603891e70e208643ad
devspaces/code-rhel9@sha256:5721cf5cede1d1f177048b897b880f35bf6208c79521d8867dfa1c0b5cd6e58d
devspaces/configbump-rhel9@sha256:ed952b1595da133948cc2f63c26f8294f1ad57dda4fc911b3e68c342f9d05ffc
devspaces/dashboard-rhel9@sha256:b7db9f8c10fa9476c9b2daa0029695c1b5ef5d03c2203ad359fcac2e97892ac9
devspaces/devspaces-operator-bundle@sha256:dfa48e044bf23c7da2cc9d18317f1ec14f591a125ef39ddfaefebbe434dcce90
devspaces/devspaces-rhel9-operator@sha256:c641190d036ca6d270a4a65f181b4e2c584a62fdc374937c71e64d2ff24ed3c0
devspaces/imagepuller-rhel9@sha256:4dcd09c3ce61afc15858db3b6adb2f6931dfb8556a686d1a96c4eebf4bb5f6bb
devspaces/machineexec-rhel9@sha256:d799111ba9af355c1ba070b591a0fb6f601b6e6e41cef5b5466146f4f8c75fc4
devspaces/pluginregistry-rhel9@sha256:768dec74e699d285d338095445229d7aaa3516ca1878dc95d4f57aee9ec3c982
devspaces/server-rhel9@sha256:c351151b5c7b20b7b425629a1f6390e3da770383ee5558060a53b91721e97426
devspaces/traefik-rhel9@sha256:6485c5b8697b6a7bf4e1d1a7894aa1d776f992e7233ac496f6ac1aa4eeb87892
devspaces/udi-rhel9@sha256:bccd955215d40f7bb4ab20554aee523476301130a96d612c729fad3cad1a75d7

s390x

devspaces-tech-preview/jetbrains-ide-rhel9@sha256:d615c925a4157a9cecc786a0456d4e630f06525d63935f504dad6627aeb85d34
devspaces/code-rhel9@sha256:71460099eab18a7308bf716446adad7f89db6801787c48506c90a6da553886be
devspaces/configbump-rhel9@sha256:35097e997aa9afb7e4d5809db7ff9b3e4164d0d56265ab89e5005d78340c0471
devspaces/dashboard-rhel9@sha256:0077e027ccac4e5d7bb75ffa9679f51405a9afa2cad62cbfad60db483c3c457c
devspaces/devspaces-operator-bundle@sha256:23ee857e916a11369454290e62a705293db4a000f2f206118d1d234ab3cf9236
devspaces/devspaces-rhel9-operator@sha256:fb0eca71563b4aaeda85e7f7cb4fc87b4ddc772802b246e88f34a91fa57d2e1a
devspaces/imagepuller-rhel9@sha256:664c3848a01aef9533a77f5cbdf388c78e9dedb8bb364b20346edadb0165de00
devspaces/machineexec-rhel9@sha256:961cb6073b19f2dc3769b8e5bae1fffbe5ee712b26744e1ff7e250cf16329106
devspaces/pluginregistry-rhel9@sha256:2f7a8b09c04abbbc29af8dfd5a8e4f5133fa467c42ed0b7d8b64724b27882b0d
devspaces/server-rhel9@sha256:bf9d3f2419c27273a4c4f586d88aa0e64c2d11a583e5dc1f1679c8d8b92d892f
devspaces/traefik-rhel9@sha256:1715902537309e3f1dbbc12bfbb25b440e6db531efcbf33e5b51d991fc979bd4
devspaces/udi-rhel9@sha256:32a9325a9909b8387fe384e0a43e1be72c9a3989b260fdfc41229bd221134e53

x86_64

devspaces-tech-preview/idea-rhel9@sha256:7a43d596b13d43bd689f9cfbc29327fb988e0ea15d8790258379943f429998b9
devspaces-tech-preview/jetbrains-ide-rhel9@sha256:99197f82cc9b3a1fb0cf9f6ec458aac5b3b7a3ebefe58cb4d7ee96ed16e88366
devspaces/code-rhel9@sha256:a58c6da36a5b402d9852a8671af976b94975d48dfe694fa600871f356814b64d
devspaces/configbump-rhel9@sha256:38eb6a388833aefb0cfcd2a1ffbe597a6b9cbbae67d22aaec4f3cae0e09292ee
devspaces/dashboard-rhel9@sha256:178678bb38a68826b7fa57766150661860c91faee6af2e73921bb4483ae36896
devspaces/devspaces-operator-bundle@sha256:a584ae6a7f9f5facfb84ca068b08c1dab9e68c8ccf0fca7d8f6e492e3eacb039
devspaces/devspaces-rhel9-operator@sha256:3878adbe4177af302b16d5e30626125d6c3a6ddd93cad20b4aee54ea54b69af0
devspaces/imagepuller-rhel9@sha256:7e7cf118995a7eaf37f909dafa40fb031f5a036de31344c51d4e944eb74bcbbc
devspaces/machineexec-rhel9@sha256:196a6811343f082a0daa0dbf2a1fd73f80d1da546f8d72073eb37027609ec45a
devspaces/pluginregistry-rhel9@sha256:58b11d05aff7b68d1a74c29a828f8cb382c5752a3fcf207b5d1d318057b7a170
devspaces/server-rhel9@sha256:587baf931fb97c939ee3c4b90510215c97d7ec790e7387e478a9c506b99b5d4a
devspaces/traefik-rhel9@sha256:b05d482bc642262bb1b5470fc9a60e74099f22d8b658edfea34a6490a32fd7dc
devspaces/udi-rhel9@sha256:abefbfd48f420988ebbdd30e8cba1f6e2d06b1ec4d38a6394d532ab16f966b9d

The Red Hat security contact is secalert@redhat.com. More contact details at https://access.redhat.com/security/team/contact/.

Red Hat LinkedIn YouTube Facebook X, formerly Twitter

Quick Links

  • Downloads
  • Subscriptions
  • Support Cases
  • Customer Service
  • Product Documentation

Help

  • Contact Us
  • Customer Portal FAQ
  • Log-in Assistance

Site Info

  • Trust Red Hat
  • Browser Support Policy
  • Accessibility
  • Awards and Recognition
  • Colophon

Related Sites

  • redhat.com
  • developers.redhat.com
  • connect.redhat.com
  • cloud.redhat.com

Red Hat legal and privacy links

  • About Red Hat
  • Jobs
  • Events
  • Locations
  • Contact Red Hat
  • Red Hat Blog
  • Inclusion at Red Hat
  • Cool Stuff Store
  • Red Hat Summit
© 2025 Red Hat

Red Hat legal and privacy links

  • Privacy statement
  • Terms of use
  • All policies and guidelines
  • Digital accessibility