CVE-2024-52011: Red Hat Cluster Observability Operator 1.5.0

High severity, CVSS 8.3. EPSS: 0.5% chance of exploitation in the next 30 days.

launch-editor allows users to open files with line numbers in editor from Node.js. Prior to version 2.9.0, due to the insufficient sanitization of the `file` argument in the `launchEditor`, an attacker can execute arbitrary commands on Windows by supplying a filename that contains special characters. This issue has been fixed in the `launch-editor` version 2.9.0, corresponding to vite version 5.4.9.

Affected products

  • Red Hat Cluster Observability Operator 1.5.0: before 1782839279 (fixed in 1782839279); before 1782840539 (fixed in 1782840539)
  • Red Hat Cryostat 4
  • Red Hat Migration Toolkit For Containers
  • Red Hat Node Healthcheck Operator
  • Red Hat Openshift Lightspeed
  • Red Hat Openshift Pipelines
  • Red Hat Openshift Service Mesh 2
  • Red Hat Openshift Service Mesh 3
  • Red Hat Red Hat Amq Broker 7
  • Red Hat Red Hat Ansible Automation Platform 2
  • Red Hat Red Hat Build Of Apache Camel - Hawtio 4
  • Red Hat Red Hat Build Of Keycloak
  • Red Hat Red Hat Build Of Podman Desktop
  • Red Hat Red Hat Build Of Podman Desktop - Tech Preview
  • Red Hat Red Hat Data Grid 8
  • Red Hat Red Hat Developer Hub
  • Red Hat Red Hat Discovery 2
  • Red Hat Red Hat Enterprise Linux Ai Rhel Ai 3
  • Red Hat Red Hat JBoss Enterprise Application Platform 8
  • Red Hat Red Hat JBoss Enterprise Application Platform Expansion Pack
  • Red Hat Red Hat Openshift Ai Rhoai
  • Red Hat Red Hat Openshift Container Platform 4
  • Red Hat Red Hat Openshift Dev Spaces
  • Red Hat Red Hat Openshift Virtualization 4
  • Red Hat Red Hat Quay 3
  • and 3 more

Published 2026-06-01. Last modified 2026-09-04.