Sceawere
Vulnerability Detail
CVE-2026-56098UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Authorization Bypass in rubygem-katello
Vulnerability Metadata
- Severity
- Medium
- Score / CVSS
- 4.3
- Creation Date
- 1d ago
- Vendor
- Red Hat
- Product
- Red Hat Satellite 6.16 for RHEL 8
- Attack Type
- Observable Discrepancy
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
- Attack Complexity
- LOW
Narrative and Response
Description
A flaw was found in rubygem-katello. The RegistryProxiesController in Katello contains an authorization bypass vulnerability due to an execution fall-through in the registry_authorize filter. While the application identifies unauthorized requests and triggers an error response via the unauthorized method, it fails to halt the execution of the current code path (missing return statement). This failure in the control flow allows the application to proceed into subsequent business logic and database validation filters. Consequently, the application reveals its internal state through differential responses, allowing an unprivileged attacker to enumerate valid Users, Organizations, and Products across the entire instance.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "4.3",
"pubDate": "2026-10-01T18:17:19.763Z",
"pubdate": "2026-10-01T18:17:19.763Z",
"executiveSummary": "The rubygem-katello package contains an authorization bypass vulnerability located within the RegistryProxiesController.\nThe flaw originates from an improper control flow in the registry_authorize filter, specifically missing a return statement after an unauthorized error trigger.\nThis vulnerability allows unauthenticated or unprivileged attackers to bypass security checks and proceed into protected business logic.\nThe impact includes unauthorized information disclosure, enabling an attacker to enumerate valid Users, Organizations, and Products within the Katello instance.\nThe vulnerability is primarily an execution fall-through issue that results in a failure to properly enforce access control policies, leading to state exposure.\nNo specific authentication or high-privilege credentials are required to leverage this flaw, as the logic error occurs prior to full request validation completion.\nThe risk is significant due to the sensitive nature of the information exposed through differential responses generated by the application.",
"technicalDetails": "The root cause of the vulnerability is an incomplete implementation of the 'registry_authorize' filter within the 'RegistryProxiesController' component of 'rubygem-katello'.\nIn Ruby on Rails controller filters, a 'before_action' or similar callback must halt the request cycle explicitly if authorization fails. The vulnerability arises because the 'registry_authorize' method calls an internal 'unauthorized' error response method but fails to return 'false' or invoke 'render plain/json ... and return' to cease execution of the subsequent code path.\nDue to the absence of the 'return' statement, the Ruby interpreter continues executing the remaining code within the controller action, even after the authorization error has been triggered. This creates an execution fall-through where the application proceeds to evaluate downstream business logic, database validation filters, and data retrieval processes.\nAn attacker can exploit this by crafting requests directed at the 'RegistryProxiesController'. When the application processes the request, the 'registry_authorize' filter flags the request as unauthorized; however, because the execution flow is not terminated, the application proceeds to access and validate against the database.\nThe attacker utilizes the resulting differential responses to determine the validity of various entities. By observing variations in HTTP status codes, error messages, or response times caused by successful or failed database queries in the subsequent logic, the attacker performs enumeration of internal resources.\nThis behavior allows for the systematic discovery of 'Users', 'Organizations', and 'Products' present in the system, effectively bypassing the intended security posture of the Katello instance.\nThe impact is a serious information disclosure vulnerability where the internal state of the application is leaked to an unprivileged actor, facilitating reconnaissance for further attacks or data harvesting. The vulnerability is persistent as long as the code execution path continues past the triggered error response in the controller filter."
}