Bug 2547765 (CVE-2026-107444) - CVE-2026-107444 rubygem-katello: Katello Docker Tags repositories API cross-organization authorization bypass
Summary: CVE-2026-107444 rubygem-katello: Katello Docker Tags repositories API cross-o...
Keywords:
Status: NEW
Alias: CVE-2026-107444
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
medium
medium
Target Milestone: ---
Assignee: Product Security
QA Contact:
URL:
Whiteboard:
Depends On:
Blocks:
TreeView+ depends on / blocked
 
Reported: 2026-10-08 03:31 UTC by OSIDB Bzimport
Modified: 2026-10-08 03:31 UTC (History)
13 users (show)

Fixed In Version:
Clone Of:
Environment:
Last Closed:
Embargoed:


Attachments (Terms of Use)

Description OSIDB Bzimport 2026-10-08 03:31:45 UTC
A flaw was found in Katello. The Docker Tags repositories API endpoint resolves a DockerMetaTag with an unscoped find and returns associated repositories without intersecting Repository.readable. An authenticated user with view_products permission in one organization can enumerate repository metadata (names, product associations, content types, upstream URLs) for Docker tags belonging to other organizations by supplying the tag identifier and omitting the optional organization filter. Reported via PSIRTSUPT-25120.


Note You need to log in before you can comment on or make changes to this bug.