Impact
The vulnerability originates in the Katello Docker Tags repositories API, which fails to enforce organization scoping when listing repositories for a Docker meta tag. An authenticated user with permission to view products in one organization can supply a tag identifier belonging to another organization and retrieve repository metadata associated with that tag. This allows unauthorized disclosure of repository configuration information across organization boundaries.
Affected Systems
The affected systems are Red Hat products that integrate Katello, notably Red Hat Satellite 6 and Red Hat Hardened Images. Any instance running Katello code that implements the Docker Tags repositories API is potentially impacted; the advisory does not list specific version numbers, so all current releases that include the vulnerable code could be affected.
Risk and Exploitability
The CVSS base score of 4.3 indicates a low severity level. Because no EPSS score is available and the vulnerability is not catalogued in the CISA KEV list, there is no evidence of active exploitation. An attacker would need authenticated access with product‑view permissions in one organization and the tag identifier of a resource in another organization, implying the attack path requires legitimate API calls from a credentialed user. Consequently, the primary risk stems from over‑permissive user roles rather than a publicly exploitable flaw.
OpenCVE Enrichment