Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-12515

Опубликовано: 17 июн. 2026
Источник: redhat
CVSS3: 4.3
EPSS Низкий

Описание

A flaw was found in Katello's of Red Hat Satellite. A content upload functionality where insufficient authorization checks in the ContentUploadsController allowed users with the edit_products permission to query content information for repositories outside the products they were authorized to manage. An authenticated attacker could exploit this issue to determine whether specific content exists within repositories that should otherwise be inaccessible. This issue does not allow unauthorized modification, import, or publication of content.

Отчет

This vulnerability affects Katello's content upload API authorization handling. Red Hat Product Security has assessed this issue as a Moderate severity vulnerability. Katello's content_uploads API does not properly enforce repository authorization checks when processing upload requests. A user with product-filtered edit_products permissions may query repositories outside their authorized scope and determine whether matching content exists within the Pulp content store. The issue arises because the API allows operations against repositories that are not covered by the caller's product-scoped permissions. The response behavior may disclose whether matching content already exists, potentially revealing information about content associated with repositories that would otherwise be inaccessible to the user. Because the impact is limited to disclosure of repository information, Red Hat assessed the Confidentiality impact as Low (C:L), with no demonstrated Integrity or Availability impact.

Меры по смягчению последствий

Red Hat is not aware of a practical temporary workaround that fully mitigates this issue or meets Red Hat Product Security's standards for usability, deployment, applicability, or stability. Customers are advised to apply the relevant security updates if they become available.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Hardened ImagesctagsNot affected
Red Hat Satellite 6satellite:el8/rubygem-katelloAffected
Red Hat Satellite 6.16 for RHEL 8rubygem-katelloFixedRHSA-2026:5022304.08.2026
Red Hat Satellite 6.16 for RHEL 9rubygem-katelloFixedRHSA-2026:5022304.08.2026
Red Hat Satellite 6.17 for RHEL 9rubygem-katelloFixedRHSA-2026:5022204.08.2026
Red Hat Satellite 6.18 for RHEL 9rubygem-katelloFixedRHSA-2026:5026304.08.2026
Red Hat Satellite 6.19 for RHEL 9rubygem-katelloFixedRHSA-2026:5022104.08.2026

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-862
https://bugzilla.redhat.com/show_bug.cgi?id=2489812katello: missing repository authorization in content_uploads exposes cross-product content existence

EPSS

Процентиль: 10%
0.00197
Низкий

4.3 Medium

CVSS3

Связанные уязвимости

CVSS3: 4.3
nvd
2 месяца назад

A flaw was found in Katello's of Red Hat Satellite. A content upload functionality where insufficient authorization checks in the ContentUploadsController allowed users with the edit_products permission to query content information for repositories outside the products they were authorized to manage. An authenticated attacker could exploit this issue to determine whether specific content exists within repositories that should otherwise be inaccessible. This issue does not allow unauthorized modification, import, or publication of content.

CVSS3: 4.3
github
2 месяца назад

katello: missing repository authorization in content_uploads exposes cross-product content existence

EPSS

Процентиль: 10%
0.00197
Низкий

4.3 Medium

CVSS3