Fedora Account System
Red Hat Associate
Red Hat Customer
Description The RegistryProxiesController in Katello contains an authorization bypass vulnerability due to an execution fall-through in the registry_authorize filter. While the application identifies unauthorized requests and triggers an error response via the unauthorized method, it fails to halt the execution of the current code path (missing return statement). This failure in the control flow allows the application to proceed into subsequent business logic and database validation filters. Consequently, the application reveals its internal state through differential responses, allowing an unprivileged attacker to enumerate valid Users, Organizations, and Products across the entire instance. -------------------------------------------------------------------------------- $ cat /usr/share/gems/gems/katello-4.20.0.rc1/app/controllers/katello/api/registry/registry_proxies_controller.rb def registry_authorize @repository = find_readable_repository return true if ['GET', 'HEAD'].include?(request.method) && @repository && !require_user_authorization? return true if authenticate_from_request(request.headers['Authorization']) unauthorized [should be: “unauthorized and return”] end def unauthorized redirect_authorization_headers render_error('unauthorized', :status => :unauthorized) false [no return here neither] end -------------------------------------------------------------------------------- Impact User Enumeration: Attackers can verify the existence of usernames. Invalid users cause a server-side crash (500 Internal Server Error) because the fall-through logic cannot handle a null user object. Valid users trigger a semantic error (404 NAME_UNKNOWN), confirming their presence. Resource Mapping: Unauthorized users can map hidden organizational structures. By observing the discrepancy between "Organization not found" and "Product not found", an attacker can confirm the existence of Organizations and Products they are explicitly forbidden from viewing. Exploit Chain Enabler: This vulnerability provides the necessary "transport" for the F-38 SQL Injection in Registry Proxy via labels, allowing malicious payloads to reach the database layer despite failing initial authorization checks. RECOMMENDATIONS Fix Control Flow: Add an explicit “and return” to the unauthorized method call within registry_authorize to ensure the filter chain terminates immediately and prevents execution fall-through. Normalize Error Responses: Configure the Registry API to return a uniform 401 Unauthorized response for all failed authorization attempts to eliminate the enumeration oracle.
This issue has been addressed in the following products: Red Hat Satellite 6.18 for RHEL 9 Via RHSA-2026:74504 https://access.redhat.com/errata/RHSA-2026:74504
This issue has been addressed in the following products: Red Hat Satellite 6.17 for RHEL 9 Via RHSA-2026:74505 https://access.redhat.com/errata/RHSA-2026:74505
This issue has been addressed in the following products: Red Hat Satellite 6.16 for RHEL 8 Red Hat Satellite 6.16 for RHEL 9 Via RHSA-2026:74506 https://access.redhat.com/errata/RHSA-2026:74506