CVE-2026-107444: fallo de gravedad media en Red Hat Hardened Images
Rubygem-katello: katello docker tags repositories api cross-organization authorization bypass
Publicada el
10Vexday Risk Score
Sin señal de explotación. Ningún artefacto público de explotación conocido hasta ahora.
ssvc Trackcvss 4.3
probabilidad de explotación
—
explotación observada
noninguna fuente lo reporta
A flaw was found in Katello where the Docker Tags repositories API does not properly enforce organization scoping when listing repositories for a Docker meta tag. An authenticated user with permission to view products in one organization may be able to retrieve repository metadata associated with Docker tags belonging to another organization by supplying the tag identifier. This can result in unauthorized disclosure of repository configuration information across organization boundaries.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
CVEs relacionadas — Red Hat Hardened Images
En el mismo producto, de las más peligrosas a las menos.
CVE-2026-6893HIGHDracut: dracut: root code execution via dhcp options command injectionEPSS 3.1%CVE-2022-3874HIGHOs command injection via ct_command and fcct_commandEPSS 2.2%CVE-2025-49796CRITICALLibxml: type confusion leads to denial of service (dos)EPSS 1.6%CVE-2026-12405HIGHRubygem-foreman_remote_execution: command injection in job invocations via effective_user parameterEPSS 1.5%CVE-2026-5121HIGHLibarchive: libarchive: arbitrary code execution via integer overflow in iso9660 image processingEPSS 1.4%CVE-2026-1961HIGHForman: foreman: remote code execution via command injection in websocket proxyEPSS 1.4%