云虫漏洞库

CVE-2026-79654 - A flaw was found in Katello where the Content View History API does not properly enforce authorization when accessing a Content View specified by the user. An authenticated user with permission to view Content Views in one organization may be able to access the lifecycle history of a Content View belonging to another organization by supplying its identifier to the affected API endpoint. This can result in unauthorized disclosure of Content View lifecycle information, including p - 漏洞详情

漏洞编号:CVE-2026-79654

风险等级:中危

漏洞来源:CVE

CVE 编号:CVE-2026-79654

CNNVD 编号:-

厂商/产品:- / -

影响范围:-

CWE:CWE-639

发布/更新时间:2026-08-26 / 2026-08-28

漏洞描述

A flaw was found in Katello where the Content View History API does not properly enforce authorization when accessing a Content View specified by the user. An authenticated user with permission to view Content Views in one organization may be able to access the lifecycle history of a Content View belonging to another organization by supplying its identifier to the affected API endpoint. This can result in unauthorized disclosure of Content View lifecycle information, including publication and promotion events, associated users, and timestamps.

相关链接

相关漏洞

« 返回首页