Impact
The vulnerability resides in the Katello component of Red Hat Satellite 6. The Content View Filter Rules API fails to enforce authorization on the parent Content View Filter. An authenticated user with limited privileges in one organization can supply the identifier of a filter in another organization and read or alter its rules, leading to unauthorized disclosure of filter‑rule data and unauthorized changes to unpublished filter configuration, effectively breaching confidentiality and integrity boundaries across tenants. The weakness is an authorization bypass (CWE‑639).
Affected Systems
Red Hat Satellite 6 is affected. No specific version range is provided in the advisory; the issue applies to all instances that use the Katello content view filter rules API. The vulnerability is relevant to customers running any organization setup within Satellite 6 that rely on cross‑organization content view filtering.
Risk and Exploitability
The CVSS score of 5.4 indicates a moderate risk. Without an EPSS score, the probability of exploitation cannot be quantified, but the vulnerability is known to exist in a product in production environments. Because the flaw is limited to users with existing content‑view permissions, it does not grant full administrative control, reducing the potential impact compared to high‑privilege exploits. Nonetheless, the ability to read and modify filter rules across tenant boundaries could significantly affect organizational data separation and control. The vulnerability is not listed in the CISA KEV catalog, so no publicly confirmed exploit is documented.
OpenCVE Enrichment