在 Katello 中发现一个安全漏洞:Content View History API 在用户指定访问某一 Content View 时,未能正确实施授权检查。拥有查看某一组织内 Content View 权限的已认证用户,可以通过向受影响的 API 端点提供另一组织中 Content View 的标识符,访问该 Content View 的生命周期历史。这可能导致未授权地泄露 Content View 的生命周期信息,包括发布和推送事件、关联用户以及时间戳等。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Red Hat | Red Hat Satellite 6 | any |
affected |
any |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Red Hat | Red Hat Satellite 6 | - |
cpe:/a:redhat:satellite:6
|
|
| Red Hat | Red Hat Satellite 6 | - |
cpe:/a:redhat:satellite:6
|
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet