Executive brief
A security vulnerability exists in Katello, a management plugin used by Red Hat Satellite to handle software subscriptions and repository content. An attacker with low-level access can send specially crafted requests to the system's API to disrupt operations or potentially view sensitive database information. This could lead to a service outage or the unauthorized exposure of internal system data.
Technical details
A SQL injection vulnerability exists in the Katello plugin for Red Hat Satellite due to improper sanitization of the 'sort_by' parameter in the '/api/hosts/bootc_images' API endpoint. An authenticated remote attacker with low privileges can inject arbitrary SQL commands into the 'ORDER BY' clause of database queries. While underlying framework protections may block some complex queries, an attacker can still trigger database errors to cause a Denial of Service (DoS) or perform Boolean-based Blind SQL injection to extract sensitive data. The issue is fixed in Katello version 4.19.1 and addressed in Red Hat Satellite via RHSA-2026:5970 and RHSA-2026:5968.
Affected products
- Red Hat katello < 4.19.1
- Red Hat Satellite 6.17, 6.18
Timeline
- 2026-03-17: disclosed
- 2026-03-17: advisory
- 2026-03-18: other: GitHub advisory reviewed
- 2026-03-26: patched: Red Hat security advisories issued