Ad

CVE-2026-103868

MEDIUM CVSS 3.1: 6,5 EPSS 0.23%
Обновлено 7 октября 2026
Red Hat
Параметр Значение
CVSS 6,5 (MEDIUM)
Тип уязвимости CWE-488
Поставщик Red Hat
Публичный эксплойт Нет

A flaw was found in pulp-container when it authenticates to an upstream registry. Basic and bearer credentials from one remote are reused for later downloads in the same worker. A user who can sync a container remote, and can point that remote at a server they control, receives the username, password, or bearer token stored for a different remote, and can reuse that credential at the upstream registry.

Content stored in Pulp is not changed, and the service is not stopped.

Характеристики атаки

Способ атаки
По сети
Атака возможна удалённо
Сложность
Низкая
Легко эксплуатировать
Нужны права
Низкие
Нужны базовые права
Участие пользователя
Не требуется
Не нужно действие пользователя

Последствия

Конфиденциальность
Высокое
Полная утечка данных
Целостность
Нет
Нет модификации данных
Доступность
Нет
Нет нарушения работы

Строка CVSS v3.1

Тип уязвимости (CWE)

Уязвимые продукты

red hat:red hat satellite 6 red hat:red hat ansible automation platform 2 red hat:red hat update infrastructure 5 red hat:red hat update infrastructure 4 for cloud providers