Fedora Account System
Red Hat Associate
Red Hat Customer
An authorization-bypass information-disclosure flaw was found in the automation-controller notification subsystem. A NotificationTemplate's notification_configuration field, which holds the notification's secret parameters, is correctly protected by prevent_search so it cannot be used as a target of the API's relational filter backend. However, each time a notification is sent, the controller copies the recipient parameter from the configuration verbatim into the recipients column of a new Notification row, and the Notification model's recipients, subject, and error columns are plain text fields with no prevent_search protection. For the notification backends whose recipient is itself a secret — PagerDuty (the Events-API service key), and Mattermost, RocketChat, and generic Webhook backends (incoming-webhook URLs that embed a bearer token) — the copied value is stored in clear text because those parameters are not encrypted password fields. Because the credential-types API endpoint is listable by any authenticated user regardless of roles, and the filter backend traverses object relations without enforcing per-hop access control, a user with no privileges and no organization membership can construct a filter that walks from credential types through credentials, organizations, notification templates, and notifications to the unprotected recipients field, and use the returned result count as a boolean oracle. Using case-insensitive, case-sensitive, and regular-expression match operators, the attacker recovers the exact secret value one character at a time, for organizations they have no access to. The same relation chain also exposes each notification's subject and error text. The result is cross-tenant disclosure of live notification credentials to an unprivileged user. The root cause is that a value stripped of search protection at the source is copied into a sink that lacks the same protection; the deeper contributing weakness is that the filter backend performs relation traversal without per-hop authorization.