Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-81668

Опубликовано: 27 авг. 2026
Источник: redhat
CVSS3: 5.4
EPSS Низкий

Описание

A flaw was found in Katello where the Content View Filter Rules API does not properly enforce authorization on the parent Content View Filter. An authenticated, low-privileged user with Content View permissions in one organization may be able to access and modify filter rules belonging to a Content View Filter in another organization by supplying that filter's identifier. This can result in unauthorized disclosure of filter-rule information and unauthorized changes to unpublished Content View filter configuration.

Отчет

Red Hat Product Security has assessed this issue as a Moderate severity vulnerability. This vulnerability affects Katello's Content View Filter Rules API authorization handling. The issue arises because the API loads the parent Content View Filter by identifier without an authorization-aware scope. Successful exploitation allows the attacker to read filter-rule metadata and to add, change, or delete rules outside their authorized organization. Those changes persist in the live filter configuration and can affect the content included in a subsequent Content View publication. Already-published Content View versions are immutable snapshots and are not modified by this flaw. Confidentiality is Low because the disclosed data is filter-rule metadata rather than repository contents or credentials. Integrity is Low because the attacker can modify unpublished filter rules, but cannot publish or promote Content Views, cannot alter already-published versions, and cannot change repository content or host state.

Меры по смягчению последствий

Red Hat is not aware of a practical temporary workaround that fully mitigates this issue or meets Red Hat Product Security's standards for usability, deployment, applicability, or stability. Customers are advised to apply the relevant security updates when they become available.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Satellite 6rubygem-katelloAffected

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-639
https://bugzilla.redhat.com/show_bug.cgi?id=2524928rubygem-katello: Cross-tenant Content View Filter rule access and modification via unauthorized parent filter lookup

EPSS

Процентиль: 4%
0.00143
Низкий

5.4 Medium

CVSS3

Связанные уязвимости

CVSS3: 5.4
nvd
20 дней назад

A flaw was found in Katello where the Content View Filter Rules API does not properly enforce authorization on the parent Content View Filter. An authenticated, low-privileged user with Content View permissions in one organization may be able to access and modify filter rules belonging to a Content View Filter in another organization by supplying that filter's identifier. This can result in unauthorized disclosure of filter-rule information and unauthorized changes to unpublished Content View filter configuration.

CVSS3: 5.4
github
20 дней назад

A flaw was found in Katello where the Content View Filter Rules API does not properly enforce authorization on the parent Content View Filter. An authenticated, low-privileged user with Content View permissions in one organization may be able to access and modify filter rules belonging to a Content View Filter in another organization by supplying that filter's identifier. This can result in unauthorized disclosure of filter-rule information and unauthorized changes to unpublished Content View filter configuration.

EPSS

Процентиль: 4%
0.00143
Низкий

5.4 Medium

CVSS3