A flaw was found in Katello where the Docker Tags repositories API does not properly enforce organization scoping when listing repositories for a Docker meta tag. An authenticated user with permission to view products in one organization may be able to retrieve repository metadata associated with Docker tags belonging to another organization by supplying the tag identifier. This can result in unauthorized disclosure of repository configuration information across organization boundaries.
Metrics
Affected Vendors & Products
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Thu, 08 Oct 2026 04:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A flaw was found in Katello where the Docker Tags repositories API does not properly enforce organization scoping when listing repositories for a Docker meta tag. An authenticated user with permission to view products in one organization may be able to retrieve repository metadata associated with Docker tags belonging to another organization by supplying the tag identifier. This can result in unauthorized disclosure of repository configuration information across organization boundaries. | |
| Title | Rubygem-katello: katello docker tags repositories api cross-organization authorization bypass | |
| First Time appeared |
Redhat
Redhat hummingbird Redhat satellite |
|
| Weaknesses | CWE-639 | |
| CPEs | cpe:/a:redhat:hummingbird:1 cpe:/a:redhat:satellite:6 |
|
| Vendors & Products |
Redhat
Redhat hummingbird Redhat satellite |
|
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: redhat
Published:
Updated: 2026-10-08T03:41:31.998Z
Reserved: 2026-10-08T03:29:12.521Z
Link: CVE-2026-107444
No data.
Status : Received
Published: 2026-10-08T04:17:14.237
Modified: 2026-10-08T04:17:14.237
Link: CVE-2026-107444
No data.
OpenCVE Enrichment
Updated: 2026-10-08T06:30:17Z
Weaknesses