Fedora Account System
Red Hat Associate
Red Hat Customer
A flaw was found in Katello. The Flatpak Remote Repositories API resolves records with an unscoped FlatpakRemoteRepository.find in a before_action used by show and mirror, while the index path correctly uses FlatpakRemoteRepository.readable. An authenticated user with view_flatpak_remotes in one organization can read another organization's flatpak remote repository metadata. The same unscoped finder backs the mirror action, which creates a repository in a product the attacker can edit using the victim organization's flatpak remote registry URL and stored remote credentials (username/token). Reported via PSIRTSUPT-25121.