在 Katello 中发现了缺陷:内容视图过滤规则 API 未对父级内容视图过滤器正确执行授权。一个拥有某个组织中内容视图权限的低权限认证用户,可能通过提供该过滤器的标识符,访问并修改另一个组织中内容视图过滤器的过滤规则。这可能导致过滤规则信息的未授权泄露,以及未授权修改未发布的内容视图过滤配置。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Red Hat | Red Hat Satellite 6 | - |
cpe:/a:redhat:satellite:6
|
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-5680 | 7.5 HIGH | Undertow-core: undertow: denial of service via websocket permessage-deflate processing |
| CVE-2026-78002 | 7.5 HIGH | Rsyslog: rsyslog: denial of service via heap buffer overflow in rainerscript replace() fun |
| CVE-2026-81658 | 6.5 MEDIUM | Foreman: cross-tenant disclosure of template revisions via unauthorized audit lookup |
No comments yet