Impact
An SQL injection flaw exists in the Red Hat Satellite Katello Registry Proxy. The application fails to sanitize input parameters inside the RegistryProxiesController when handling user-supplied labels from the request path. User input is interpolated directly into raw SQL fragments in methods such as check_blob_push_org_label and get_matching_products_from_org. The vulnerability can lead to unauthorized reading or modification of registry data and potentially enable privilege escalation, since it is exploitable by any user who has the create_personal_access_tokens permission, even without an assigned organization or location.
Affected Systems
The affected systems are Red Hat Satellite 6, including the 6.19 release for RHEL 9. The vulnerability directly impacts the Satellite and its related components such as Satellite Capsule and Satellite Utils as part of the 6.19 update set for EL9.
Risk and Exploitability
The CVSS score of 6.5 indicates a moderate severity, and the EPSS score is currently unavailable. The vulnerability is not listed in the CISA KEV catalog. There is no available workaround that meets Red Hat Product Security criteria; the only provided options are considered insufficient. The likely attack vector involves sending crafted HTTP requests to the Registry Proxy endpoint with malicious labels. An attacker only needs the create_personal_access_tokens permission and does not require organizational context, making the exploit readily achievable in the target environment. Given the potential impact on data confidentiality and integrity, organizations should assess the risk quickly and apply the recommended mitigation steps.
OpenCVE Enrichment