No analysis available yet.
Vendor Workaround
Red Hat is not aware of a practical temporary workaround that fully mitigates this issue or meets Red Hat Product Security's standards for usability, deployment, applicability, or stability. Customers are advised to apply the relevant security updates when they become available.
Tracking
Sign in to view the affected projects.
No advisories yet.
Wed, 07 Oct 2026 06:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A flaw was found in pulp-container when it authenticates to an upstream registry. Basic and bearer credentials from one remote are reused for later downloads in the same worker. A user who can sync a container remote, and can point that remote at a server they control, receives the username, password, or bearer token stored for a different remote, and can reuse that credential at the upstream registry. Content stored in Pulp is not changed, and the service is not stopped. | |
| Title | Pulp-container: registry credentials are reused across remotes in a worker | |
| First Time appeared |
Redhat
Redhat ansible Automation Platform Redhat rhui Redhat satellite |
|
| Weaknesses | CWE-488 | |
| CPEs | cpe:/a:redhat:ansible_automation_platform:2 cpe:/a:redhat:rhui:4::el8 cpe:/a:redhat:rhui:5::el9 cpe:/a:redhat:satellite:6 |
|
| Vendors & Products |
Redhat
Redhat ansible Automation Platform Redhat rhui Redhat satellite |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: redhat
Published:
Updated: 2026-10-07T07:19:15.916Z
Reserved: 2026-10-01T11:51:10.971Z
Link: CVE-2026-103868
No data.
Status : Received
Published: 2026-10-07T06:16:35.000
Modified: 2026-10-07T07:16:57.363
Link: CVE-2026-103868
No data.
OpenCVE Enrichment
No data.
-
CWE-488
Exposure of Data Element to Wrong Session