Bug 2547766 (CVE-2026-107445) - CVE-2026-107445 rubygem-katello: Katello Flatpak Remote Repositories API cross-organization authorization bypass
Summary: CVE-2026-107445 rubygem-katello: Katello Flatpak Remote Repositories API cros...
Keywords:
Status: NEW
Alias: CVE-2026-107445
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
medium
medium
Target Milestone: ---
Assignee: Product Security
QA Contact:
URL:
Whiteboard:
Depends On:
Blocks:
TreeView+ depends on / blocked
 
Reported: 2026-10-08 03:31 UTC by OSIDB Bzimport
Modified: 2026-10-08 03:31 UTC (History)
13 users (show)

Fixed In Version:
Clone Of:
Environment:
Last Closed:
Embargoed:


Attachments (Terms of Use)

Description OSIDB Bzimport 2026-10-08 03:31:50 UTC
A flaw was found in Katello. The Flatpak Remote Repositories API resolves records with an unscoped FlatpakRemoteRepository.find in a before_action used by show and mirror, while the index path correctly uses FlatpakRemoteRepository.readable. An authenticated user with view_flatpak_remotes in one organization can read another organization's flatpak remote repository metadata. The same unscoped finder backs the mirror action, which creates a repository in a product the attacker can edit using the victim organization's flatpak remote registry URL and stored remote credentials (username/token). Reported via PSIRTSUPT-25121.


Note You need to log in before you can comment on or make changes to this bug.