Bug 2448349 (CVE-2026-4324) - CVE-2026-4324 rubygem-katello: Katello: Denial of Service and potential information disclosure via SQL injection
Summary: CVE-2026-4324 rubygem-katello: Katello: Denial of Service and potential infor...
Keywords:
Status: NEW
Alias: CVE-2026-4324
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
medium
medium
Target Milestone: ---
Assignee: Product Security
QA Contact:
URL:
Whiteboard:
Depends On:
Blocks:
TreeView+ depends on / blocked
 
Reported: 2026-03-17 12:32 UTC by OSIDB Bzimport
Modified: 2026-03-17 13:19 UTC (History)
12 users (show)

Fixed In Version:
Clone Of:
Environment:
Last Closed:
Embargoed:


Attachments (Terms of Use)

Description OSIDB Bzimport 2026-03-17 12:32:57 UTC
A flaw was found in the Katello plugin for Red Hat Satellite. The vulnerability occurs due to improper sanitization of user-provided input in the sort_by parameter of the /api/hosts/bootc_images API endpoint. An attacker could exploit this flaw by injecting arbitrary SQL commands into the order clause of the database query. While certain complex queries are blocked by the underlying framework's protections, an attacker can still manipulate the query structure to trigger database errors, cause a Denial of Service (DoS), or potentially perform Boolean-based Blind SQL injection.


Note You need to log in before you can comment on or make changes to this bug.