← voltar
CVE-2026-81668mediumCWE-639

Rubygem-katello: cross-tenant content view filter rule access and modification via unauthorized parent filter lookup

13Vexday Risk Score

Sem sinal de exploração. Nenhum artefato público de exploração conhecido até agora.

ssvc Trackcvss 5.4epss 0.2%
probabilidade de exploração
0.2%top 87% das CVEs
exploração observada
nãonenhuma fonte reporta
A flaw was found in Katello where the Content View Filter Rules API does not properly enforce authorization on the parent Content View Filter. An authenticated, low-privileged user with Content View permissions in one organization may be able to access and modify filter rules belonging to a Content View Filter in another organization by supplying that filter's identifier. This can result in unauthorized disclosure of filter-rule information and unauthorized changes to unpublished Content View filter configuration.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N