Sceawere

Vulnerability Detail

CVE-2026-103868UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Pulp-container Credential Leakage Vulnerability

Vulnerability Metadata

Severity
Medium
Score / CVSS
6.5
Creation Date
4h ago
Vendor
Red Hat
Product
Red Hat Ansible Automation Platform 2
Attack Type
Exposure of Data Element to Wrong Session
Vector String
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Attack Complexity
LOW

Narrative and Response

Description

A flaw was found in pulp-container when it authenticates to an upstream registry. Basic and bearer credentials from one remote are reused for later downloads in the same worker. A user who can sync a container remote, and can point that remote at a server they control, receives the username, password, or bearer token stored for a different remote, and can reuse that credential at the upstream registry. Content stored in Pulp is not changed, and the service is not stopped.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "6.5",
  "pubDate": "2026-10-07T06:16:35.000Z",
  "pubdate": "2026-10-07T06:16:35.000Z",
  "executiveSummary": "A credential exposure vulnerability exists within the pulp-container component, specifically affecting how it handles authentication credentials when interacting with upstream registries.\nThe flaw involves the improper reuse of Basic and bearer authentication credentials across distinct remote sync operations performed by the same worker process.\nAn attacker with the capability to configure a container remote can maliciously point it toward an adversary-controlled server.\nBy triggering a sync operation against this controlled endpoint, the attacker can force the system to disclose sensitive authentication credentials (usernames, passwords, or bearer tokens) that were intended exclusively for other, unrelated remote configurations.\nThis leads to unauthorized credential exposure, allowing the attacker to impersonate the legitimate Pulp service when authenticating to the victim's upstream registries.\nThe impact is significant, as it grants unauthorized access to third-party container registries, potentially allowing for unauthorized data access or registry manipulation.\nThe integrity of existing content stored within the Pulp platform remains unaffected, and the availability of the service is not compromised by this specific flaw.",
  "technicalDetails": "The root cause of this vulnerability lies in an improper state management flaw within the pulp-container worker execution model. When the worker process performs authentication for a remote registry sync, it establishes a session context that is not properly isolated between consecutive operations.\nSpecifically, the worker retains credentials—both Basic authentication and bearer tokens—acquired during an initial authentication event. If a subsequent task is assigned to the same worker, these cached credentials are erroneously reused for the next request, even if the target remote registry and required security context differ.\nThe attack flow proceeds as follows: First, the attacker identifies a legitimate Pulp instance where they possess the necessary privileges to configure a container remote. Second, the attacker creates or modifies a container remote, setting its destination URL to an attacker-controlled endpoint capable of capturing HTTP requests.\nThird, the attacker initiates a synchronization process for this remote. As the pulp-container worker executes the sync task, it attempts to authenticate against the malicious endpoint.\nFourth, due to the session persistence defect, the worker process injects the credentials associated with a different, previously processed remote (which may have been configured for a sensitive upstream registry) into the request headers sent to the attacker's server.\nFifth, the attacker's server logs these captured headers, effectively extracting the victim's credentials.\nThis exploitation requires the ability to configure remotes within the Pulp environment. There are no specialized network requirements other than the ability for the worker to reach the attacker's endpoint. Once the credentials are obtained, the attacker can utilize them to perform unauthorized authenticated requests against the target upstream registries, potentially gaining access to private images or repositories. The vulnerability demonstrates a failure in the security boundary between distinct tasks handled by a single persistent worker process, leading to cross-contamination of sensitive authentication material. This flaw persists throughout the lifetime of the worker, and until the internal credential cache is cleared or the worker process is recycled, all subsequent sync tasks are at risk of disclosing the cached secrets to any endpoint reached by the worker."
}
CVE-2026-103868: Pulp-container Credential Leakage Vulnerability (MEDIUM Severity, CVSS: 6.5) | Sceawere