Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Thu, 08 Oct 2026 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 08 Oct 2026 12:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
| |
| Metrics |
threat_severity
|
threat_severity
|
Thu, 08 Oct 2026 04:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A flaw was found in Katello where the Docker Tags repositories API does not properly enforce organization scoping when listing repositories for a Docker meta tag. An authenticated user with permission to view products in one organization may be able to retrieve repository metadata associated with Docker tags belonging to another organization by supplying the tag identifier. This can result in unauthorized disclosure of repository configuration information across organization boundaries. | |
| Title | Rubygem-katello: katello docker tags repositories api cross-organization authorization bypass | |
| First Time appeared |
Redhat
Redhat hummingbird Redhat satellite |
|
| Weaknesses | CWE-639 | |
| CPEs | cpe:/a:redhat:hummingbird:1 cpe:/a:redhat:satellite:6 |
|
| Vendors & Products |
Redhat
Redhat hummingbird Redhat satellite |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: redhat
Published:
Updated: 2026-10-08T14:31:32.031Z
Reserved: 2026-10-08T03:29:12.521Z
Link: CVE-2026-107444
Updated: 2026-10-08T14:31:26.677Z
Status : Received
Published: 2026-10-08T04:17:14.237
Modified: 2026-10-08T15:17:42.740
Link: CVE-2026-107444
OpenCVE Enrichment
Updated: 2026-10-08T06:30:17Z