GPU VulnDB

Database/Control plane, storage & DevOps

Katello: Docker Tags API leaks repository metadata across organization boundaries

CVSS 4.3CVE-2026-107444Control plane, storage & DevOpscurated

Impact

The Docker Tags repositories API does not enforce organization scoping: a user authorized to view products in one organization can supply a tag identifier and read repository metadata belonging to a different organization. On a Satellite or Katello instance that serves as the container registry and content source for several teams or customers, the organization boundary is the tenancy boundary, and this punches a read hole in it. What leaks is repository configuration metadata - names, upstream and repo settings - not image content or credentials, so the consequence is reconnaissance into another tenant's software supply chain rather than direct compromise.

Who can reach it

A remote, authenticated Satellite/Katello user holding view-products permission in any one organization. No administrative privilege and no user interaction required.

What to do

Apply the Satellite 6 / Katello update when Red Hat publishes it; this is a service-side package update and restart of the Satellite services, with no change needed on managed hosts. Fixed versions are not stated in this record - track the Red Hat CVE page and Bugzilla 2547765. There is no described workaround short of tightening which accounts hold view-products in multi-organization instances.

References

Related entries

All Control plane, storage & DevOps entries

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.