GHSA-c43c-rf7g-5xpg

Suggest an improvement
Source
https://github.com/advisories/GHSA-c43c-rf7g-5xpg
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/06/GHSA-c43c-rf7g-5xpg/GHSA-c43c-rf7g-5xpg.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-c43c-rf7g-5xpg
Aliases
  • CVE-2026-12515
Published
2026-06-17T18:35:57Z
Modified
2026-06-18T14:45:17.804055855Z
Severity
  • 4.3 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N CVSS Calculator
Summary
katello: missing repository authorization in content_uploads exposes cross-product content existence
Details

A flaw was found in Katello's of Red Hat Satellite. A content upload functionality where insufficient authorization checks in the ContentUploadsController allowed users with the edit_products permission to query content information for repositories outside the products they were authorized to manage. An authenticated attacker could exploit this issue to determine whether specific content exists within repositories that should otherwise be inaccessible. This issue does not allow unauthorized modification, import, or publication of content.

Database specific
{
    "nvd_published_at": "2026-06-17T17:16:42Z",
    "github_reviewed_at": "2026-06-18T14:39:16Z",
    "github_reviewed": true,
    "severity": "MODERATE",
    "cwe_ids": [
        "CWE-862"
    ]
}
References

Affected packages

RubyGems / katello

Package

Name
katello
Purl
pkg:gem/katello

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
4.21.0.rc1

Affected versions

1.*
1.5.0
2.*
2.2.2
2.4.0.rc1
2.4.0.rc2
2.4.0.rc3
2.4.0
2.4.1
2.4.2
2.4.3
2.4.4
2.4.5
3.*
3.0.0.rc1
3.0.0.rc2
3.0.0.rc3
3.0.0.rc4
3.0.0.rc5
3.0.0.rc7
3.0.0
3.0.1
3.0.2
3.1.0.rc1
3.1.0.rc2.1
3.1.0
3.1.0.1
3.2.0.rc1
3.2.0.rc1.1
3.2.0.rc2
3.2.0.rc3
3.2.0
3.2.1
3.2.1.1
3.3.0.rc1
3.3.0.rc1.1
3.3.0.rc2
3.3.0
3.3.0.1
3.3.1
3.3.1.1
3.3.2
3.4.0.rc1
3.4.0.rc2
3.4.0
3.4.0.1
3.4.0.2
3.4.1
3.4.2
3.4.4
3.4.5
3.5.0.rc1
3.5.0.rc2
3.5.0
3.5.0.1
3.5.1
3.5.1.1
3.5.2
3.6.0.rc1
3.6.0.rc2
3.6.0
3.6.0.1.rc2
3.7.0.rc1
3.7.0.rc2
3.7.0
3.7.1
3.7.1.1
3.8.0.rc1
3.8.0.rc2
3.8.0.rc3
3.8.0
3.8.1
3.9.0.rc1
3.9.0.rc2
3.9.0
3.9.1
3.10.0.rc1
3.10.0.rc1.1
3.10.0
3.10.1
3.10.1.1
3.10.2
3.11.0.rc1
3.11.0.rc2
3.11.0
3.11.1
3.11.2
3.12.0.rc1
3.12.0.rc2
3.12.0
3.12.1
3.12.2
3.12.3
3.13.0.rc1
3.13.0.rc2
3.13.0.rc2.1
3.13.0
3.13.1
3.13.2
3.13.3
3.13.4
3.14.0.rc1
3.14.0.rc2
3.14.0
3.14.1
3.15.0.rc1
3.15.0.rc1.1
3.15.0.rc1.2
3.15.0.rc1.3
3.15.0.rc2
3.15.0
3.15.0.1
3.15.1
3.15.1.1
3.15.2
3.15.3
3.15.3.1
3.16.0.rc1
3.16.0.rc1.1
3.16.0.rc2
3.16.0.rc2.1
3.16.0.rc3
3.16.0.rc3.1
3.16.0.rc4
3.16.0.rc4.1
3.16.0.rc5
3.16.0.rc5.1
3.16.0
3.16.1
3.16.1.1
3.16.1.2
3.16.2
3.17.0.rc1
3.17.0.rc2
3.17.0.rc2.1
3.17.0.rc2.2
3.17.0
3.17.1
3.17.2
3.17.3
3.18.0.rc1
3.18.0.rc2
3.18.0.rc2.1
3.18.0
3.18.1
3.18.1.1
3.18.2
3.18.2.1
3.18.3
3.18.3.1
3.18.4
3.18.5
4.*
4.0.0.rc1
4.0.0.rc2
4.0.0.rc3
4.0.0.rc3.1
4.0.0
4.0.1
4.0.1.1
4.0.1.2
4.0.2
4.0.2.1
4.0.3
4.1.0.rc1
4.1.0.rc1.1
4.1.0.rc2
4.1.0.rc2.1
4.1.0.rc2.2
4.1.0
4.1.1
4.1.2
4.1.2.1
4.1.3
4.1.4
4.2.0.rc1
4.2.0.rc2
4.2.0.1.rc2
4.2.0.1.rc3
4.2.0.1
4.2.1
4.2.2
4.3.0.rc1
4.3.0.rc2
4.3.0.rc2.1
4.3.0.rc3
4.3.0.rc4
4.3.0
4.3.1
4.4.0.rc1
4.4.0.rc2
4.4.0
4.4.0.1
4.4.0.2
4.4.1
4.4.2
4.4.2.1
4.4.2.2
4.5.0.rc1
4.5.0.rc2
4.5.0
4.5.1
4.6.0.rc1
4.6.0.rc2
4.6.0
4.6.1
4.6.2
4.6.2.1
4.7.0.rc1
4.7.0.rc2
4.7.0
4.7.1
4.7.2
4.7.3
4.7.4
4.7.5
4.7.6
4.8.0.rc1
4.8.0.rc2
4.8.0
4.8.1
4.8.2
4.8.3
4.8.4
4.9.0.rc1
4.9.0.rc2
4.9.0
4.9.1
4.9.2
4.10.0.rc1
4.10.0.rc2
4.10.0
4.11.0.rc1
4.11.0.rc2
4.11.0
4.11.1
4.12.0.rc1
4.12.0.rc2
4.12.0.rc3
4.12.0
4.12.1
4.13.0.rc1
4.13.0
4.13.1
4.14.0.rc1
4.14.0.rc1.1
4.14.0.rc2
4.14.0.rc3
4.14.0
4.14.1
4.14.2
4.14.3
4.15.0.rc1
4.15.0.rc2
4.15.0
4.15.1
4.16.0.rc1
4.16.0.rc2
4.16.0
4.16.1
4.16.2
4.16.3
4.17.0.rc1
4.17.0.rc2
4.17.0
4.17.1
4.17.2
4.18.0.rc1
4.18.0.rc2
4.18.0
4.18.1
4.19.0.rc1
4.19.0.rc2
4.19.0.1
4.19.1
4.19.2
4.20.0.rc1
4.20.0.rc2
4.20.0
4.20.1

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/06/GHSA-c43c-rf7g-5xpg/GHSA-c43c-rf7g-5xpg.json"