Impact
Katello's Content View History API fails to enforce proper authorization, allowing an authenticated user who has rights in one organization to retrieve history data for a content view belonging to another organization. The attacker can view publication and promotion events, the users that performed those actions, and timestamps, exposing confidential lifecycle information and enabling further strategic attacks.
Affected Systems
The flaw affects Red Hat Satellite 6, the enterprise content management system built on Katello. All deployments of Satellite 6 are potentially vulnerable, as the vendor has not identified a specific patch version that isolates the issue.
Risk and Exploitability
The vulnerability is exploitable by any authenticated user with view permissions in at least one organization; the attacker supplies a target content view ID from another organization to the API endpoint, bypassing the authorization checks. The impact is limited to data disclosure; there is no privilege escalation or denial of service. The CVSS score of 4.3 reflects moderate risk, and the EPSS score is not available, so the current exploitation probability cannot be quantified. The issue is not listed in the CISA KEV catalog, indicating that no confirmed exploitation campaigns have been reported. Customers should monitor security advisories and apply patches as soon as they become available.
OpenCVE Enrichment