Bug 2490543 (CVE-2026-56097) - CVE-2026-56097 rubygem-katello: SQL injection in Registry Proxy via labels
Summary: CVE-2026-56097 rubygem-katello: SQL injection in Registry Proxy via labels
Keywords:
Status: NEW
Alias: CVE-2026-56097
Deadline: 2026-10-01
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
medium
medium
Target Milestone: ---
Assignee: Product Security
QA Contact:
URL:
Whiteboard:
Depends On:
Blocks:
TreeView+ depends on / blocked
 
Reported: 2026-06-18 19:00 UTC by OSIDB Bzimport
Modified: 2026-10-01 13:09 UTC (History)
14 users (show)

Fixed In Version:
Clone Of:
Environment:
Last Closed:
Embargoed:


Attachments (Terms of Use)

Description OSIDB Bzimport 2026-06-18 19:00:01 UTC
Description

An authenticated SQL injection vulnerability exists in the Red Hat Satellite Katello Registry Proxy. The application fails to sanitize input parameters used in database queries within the RegistryProxiesController.

Specifically, the methods check_blob_push_org_label and get_matching_products_from_org take user-supplied labels directly from the request path and interpolate them into raw SQL fragments.

Crucially, this vulnerability is accessible to a user possessing only the create_personal_access_tokens permission (See F-36 Improper Authorization logic allows Resource Enumeration and F-37 Improper RBAC Mapping and Missing Filters Enable Unauthorized Controller Access). Even if the user access is restricted, with no Organization or Location assigned.

Affected Code in app/controllers/katello/api/registry/registry_proxies_controller.rb:

--------------------------------------------------------------------------------

Organization lookup

org = Organization.where("LOWER(label) = '#{org_label}'") # convert to lowercase

Product lookup

return organization.products.where("LOWER(label) = '#{product_label}'") # convert to lowercase

--------------------------------------------------------------------------------

Impact

Global Data Exfiltration: Low privileged users can bypass all logical data separation and multi-tenancy restrictions to dump the entire PostgreSQL database, including sensitive tables such as users and settings.

Vertical Privilege Escalation: By exfiltrating the users table, password hashes for administrative accounts (e.g., admin) can be recovered and cracked offline. No cleartext credentials were found, other sensitive credentials such as PATs and session_id are also hashed.

The Ruby pg driver used by ActiveRecord does not support stacked queries. This prevents the execution of direct DML/DDL statements (e.g., UPDATE, INSERT, DROP) through this specific injection vector. Therefore, the injection context is limited to SELECT statement fragments.

Recommendations

Implement Parameterized Queries: Modify RegistryProxiesController to use ActiveRecord's parameterized query syntax.

Proposed Fixes:

--------------------------------------------------------------------------------

org = Organization.where("LOWER(label) = ?", org_label.downcase)

return organization.products.where("LOWER(label) = ?", product_label.downcase)

--------------------------------------------------------------------------------

Apply Authorization Controls: Enforce a check to ensure the user has permissions for the specific Organization/Product before performing the database lookup.


Note You need to log in before you can comment on or make changes to this bug.