Tracking
Sign in to view the affected projects.
No advisories yet.
Solution
No solution given by the vendor.
Workaround
Apply the security best practices from the Red Hat OpenShift Dev Spaces Administration Guide: https://docs.redhat.com/en/documentation/red_hat_openshift_dev_spaces/3.24/html/administration_guide/security-best-practices
Wed, 21 Jan 2026 22:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs |
Tue, 13 Jan 2026 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 13 Jan 2026 15:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | No description is available for this CVE. | A flaw was found in Eclipse Che che-machine-exec. This vulnerability allows unauthenticated remote arbitrary command execution and secret exfiltration (SSH keys, tokens, etc.) from other users' Developer Workspace containers, via an unauthenticated JSON-RPC / websocket API exposed on TCP port 3333. |
| Title | github.com/che-incubator/che-code: Eclipse Che — unauthenticated RCE and secret exfiltration via TCP/3333 | Github.com/che-incubator/che-code: eclipse che — unauthenticated rce and secret exfiltration via tcp/3333 |
| First Time appeared |
Redhat
Redhat openshift Devspaces |
|
| CPEs | cpe:/a:redhat:openshift_devspaces:3.22::el9 cpe:/a:redhat:openshift_devspaces:3.23::el9 cpe:/a:redhat:openshift_devspaces:3.24::el9 cpe:/a:redhat:openshift_devspaces:3: |
|
| Vendors & Products |
Redhat
Redhat openshift Devspaces |
|
| References |
|
Tue, 02 Dec 2025 12:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | No description is available for this CVE. | |
| Title | github.com/che-incubator/che-code: Eclipse Che — unauthenticated RCE and secret exfiltration via TCP/3333 | |
| Weaknesses | CWE-306 | |
| References |
| |
| Metrics |
threat_severity
|
cvssV3_1
|
Status: PUBLISHED
Assigner: redhat
Published:
Updated: 2026-01-21T22:19:04.636Z
Reserved: 2025-10-31T14:14:59.157Z
Link: CVE-2025-12548
Updated: 2026-01-13T15:51:16.262Z
Status : Awaiting Analysis
Published: 2026-01-13T16:15:55.527
Modified: 2026-01-14T16:26:00.933
Link: CVE-2025-12548
OpenCVE Enrichment
No data.