Executive brief
Katello is Red Hat's content and configuration management system used to manage packages, repositories, and content views across multiple organizations. A flaw in the Content View History API allows authenticated users to view lifecycle information of content views from organizations they don't belong to, potentially exposing details about publication events, promotion activities, and associated users.
Technical details
The vulnerability is an authorization bypass (CWE-639) in Katello's Content View History API endpoint. An authenticated user with view_content_views permission in one organization can access the lifecycle history of Content Views belonging to another organization by providing the Content View's identifier. The API fails to properly enforce authorization checks on the specified Content View resource. No user interaction is required; the attack is network-accessible and requires only a valid authenticated session with minimal privileges. The exposure is limited to unauthorized disclosure of Content View metadata (publication events, promotion events, usernames, timestamps) and does not grant access to repository contents, credentials, or modification capabilities.
Affected products
- Red Hat Katello <UNKNOWN>
Timeline
- 2026-08-26: disclosed
- other: GitHub PR 11847 and Bugzilla 2523348 reference fixes