Impact
An authenticated user with limited template permissions, such as view_ptables, can request an audited template revision by providing an audit ID. Because the endpoint does not enforce object‑level authorization, the user receives historical template contents that belong to a different organization or location. These contents may include sensitive configuration data, credentials, or other secrets, leading to an unauthorized disclosure of confidential information.
Affected Systems
Red Hat Satellite 6.
Risk and Exploitability
The flaw carries a CVSS score of 6.5, indicating a moderate overall severity. The EPSS score is unavailable, and the vulnerability is not listed in the CISA KEV catalog, suggesting it is not a known actively exploited weakness in the wild. An attacker must be authenticated and possess a template‑related permission to exploit the issue, but once authenticated, the attacker can retrieve data from any tenant without additional privileges. The combination of a moderate CVSS score and the need for only lenient permissions results in a non‑low but reasonable risk for environments where tenant isolation is critical.
OpenCVE Enrichment