发现 Katello 中的一个缺陷,其 Flatpak 远程仓库 API 在使用标识符访问 Flatpak 远程仓库时,未能正确执行授权检查。拥有查看某一组织中 Flatpak 远程仓库权限的已认证用户,可能能够访问属于其他组织的 Flatpak 远程仓库信息。同步(mirror)操作使用了相同的无范围限制(unscoped)查找方式,这可能导致用户能够创建一个属于其有编辑权限的产品中的仓库,该仓库配置了另一组织的 Flatpak 远程 URL 并存储了对应的远程凭据。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Red Hat | Red Hat Hardened Images | - |
cpe:/a:redhat:hummingbird:1
|
|
| Red Hat | Red Hat Satellite 6 | - |
cpe:/a:redhat:satellite:6
|
|
| Red Hat | Red Hat Satellite 6 | - |
cpe:/a:redhat:satellite:6
|
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-107466 | 6.1 MEDIUM | Flatpak-builder: local file exfiltration via `file |
| CVE-2026-107444 | 4.3 MEDIUM | Rubygem-katello: katello docker tags repositories api cross-organization authorization byp |
No comments yet