Fedora Account System
Red Hat Associate
Red Hat Customer
RegistryAuthHttpDownloader.registry_auth is a class attribute (pulp_container/app/downloaders.py). Every instance in the worker shares one basic-auth value and one bearer token. A later download in that process, including another remote, task, or domain, sends the Authorization header stored by an earlier authenticated sync. Remote username, password, and client_key are write-only on the API, so the syncing account cannot read them back. The caller obtains them by pointing a remote they can sync at a server they control. Introduced in dbef26e7, first release 1.3.0. This is a separate CVE from the pulp-ansible token cache: different repository, independently fixable.