Impact
The Flatpak Remote Repositories API in Katello does not properly enforce authorization when an authenticated user retrieves a flatpak remote repository by its identifier. A user with view permission in one organization may be able to read repository information from another organization and may invoke the mirror action to create a repository in a product the user can edit. The consequences include unintended disclosure of repository details and the potential to configure a product with a remote URL and credentials from another organization, which may lead to further unauthorized changes or data leakage.
Affected Systems
The vulnerability affects Katello, which is part of Red Hat Hardened Images and Red Hat Satellite 6. Specific impacted versions are not listed in the advisory, so any deployment using a Katello instance before a patch may be vulnerable.
Risk and Exploitability
The CVSS score of 5.4 indicates a moderate impact. EPSS information is unavailable and the issue is not listed in the CISA KEV catalog, suggesting that it has not yet been widely exploited. The attack requires an authenticated user with flatpak remote view permission and is likely performed via the exposed API over the network. While the exploit risk is moderate, the cross‑organization reach makes it a noteworthy concern for environments with multiple orgs accessing shared resources.
OpenCVE Enrichment