Fedora Account System
Red Hat Associate
Red Hat Customer
Description An authenticated SQL injection vulnerability exists in the Red Hat Satellite Katello Registry Proxy. The application fails to sanitize input parameters used in database queries within the RegistryProxiesController. Specifically, the methods check_blob_push_org_label and get_matching_products_from_org take user-supplied labels directly from the request path and interpolate them into raw SQL fragments. Crucially, this vulnerability is accessible to a user possessing only the create_personal_access_tokens permission (See F-36 Improper Authorization logic allows Resource Enumeration and F-37 Improper RBAC Mapping and Missing Filters Enable Unauthorized Controller Access). Even if the user access is restricted, with no Organization or Location assigned. Affected Code in app/controllers/katello/api/registry/registry_proxies_controller.rb: -------------------------------------------------------------------------------- Organization lookup org = Organization.where("LOWER(label) = '#{org_label}'") # convert to lowercase Product lookup return organization.products.where("LOWER(label) = '#{product_label}'") # convert to lowercase -------------------------------------------------------------------------------- Impact Global Data Exfiltration: Low privileged users can bypass all logical data separation and multi-tenancy restrictions to dump the entire PostgreSQL database, including sensitive tables such as users and settings. Vertical Privilege Escalation: By exfiltrating the users table, password hashes for administrative accounts (e.g., admin) can be recovered and cracked offline. No cleartext credentials were found, other sensitive credentials such as PATs and session_id are also hashed. The Ruby pg driver used by ActiveRecord does not support stacked queries. This prevents the execution of direct DML/DDL statements (e.g., UPDATE, INSERT, DROP) through this specific injection vector. Therefore, the injection context is limited to SELECT statement fragments. Recommendations Implement Parameterized Queries: Modify RegistryProxiesController to use ActiveRecord's parameterized query syntax. Proposed Fixes: -------------------------------------------------------------------------------- org = Organization.where("LOWER(label) = ?", org_label.downcase) return organization.products.where("LOWER(label) = ?", product_label.downcase) -------------------------------------------------------------------------------- Apply Authorization Controls: Enforce a check to ensure the user has permissions for the specific Organization/Product before performing the database lookup.