CVE-2026-56097: Rubygem-katello: sql injection in registry proxy via labels
A flaw was found in rubygem-katello. An SQL injection vulnerability exists in the Red Hat Satellite Katello Registry Proxy. The application fails to sanitize input parameters used in database queries within the RegistryProxiesController. The methods checkblobpushorglabel and getmatchingproductsfromorg take user-supplied labels directly from the request path and interpolate them into raw SQL fragments. This flaw is accessible to a user with only the createpersonalaccesstokens permission, even if the user access is restricted, with no Organization or Location assigned.
Other sources
Description
An authenticated SQL injection vulnerability exists in the Red Hat Satellite Katello Registry Proxy. The application fails to sanitize input parameters used in database queries within the RegistryProxiesController.
Specifically, the methods checkblobpushorglabel and getmatchingproductsfromorg take user-supplied labels directly from the request path and interpolate them into raw SQL fragments.
Crucially, this vulnerability is accessible to a user possessing only the createpersonalaccesstokens permission (See F-36 Improper Authorization logic allows Resource Enumeration and F-37 Improper RBAC Mapping and Missing Filters Enable Unauthorized Controller Access). Even if the user access is restricted, with no Organization or Location assigned.
Affected Code in app/controllers/katello/api/registry/registryproxiescontroller.rb:
--------------------------------------------------------------------------------
Organization lookup
org = Organization.where("LOWER(label) = '#{orglabel}'") # convert to lowercase
Product lookup
return organization.products.where("LOWER(label) = '#{productlabel}'") # convert to lowercase
--------------------------------------------------------------------------------
Impact
Global Data Exfiltration: Low privileged users can bypass all logical data separation and multi-tenancy restrictions to dump the entire PostgreSQL database, including sensitive tables such as users and settings.
Vertical Privilege Escalation: By exfiltrating the users table, password hashes for administrative accounts (e.g., admin) can be recovered and cracked offline. No cleartext credentials were found, other sensitive credentials such as PATs and sessionid are also hashed.
The Ruby pg driver used by ActiveRecord does not support stacked queries. This prevents the execution of direct DML/DDL statements (e.g., UPDATE, INSERT, DROP) through this specific injection vector. Therefore, the injection context is limited to SELECT statement fragments.
Recommendations
Implement Parameterized Queries: Modify RegistryProxiesController to use ActiveRecord's parameterized query syntax.
Proposed Fixes:
--------------------------------------------------------------------------------
org = Organization.where("LOWER(label) = ?", orglabel.downcase)
return organization.products.where("LOWER(label) = ?", productlabel.downcase)
--------------------------------------------------------------------------------
Apply Authorization Controls: Enforce a check to ensure the user has permissions for the specific Organization/Product before performing the database lookup.
— Red Hat
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
rubygem-katelloto a version that resolves this vulnerability.Fixed in 4.21.2 - Upgrade
Upgrade
rubygem-katelloto a version that resolves this vulnerability.Fixed in 5.0.1 - Compensating control
In RegistryProxiesController, enforce a permission check confirming the user is authorized for the specific Organization and Product before performing the database lookup.
- Compensating control
Modify check_blob_push_org_label and get_matching_products_from_org to use ActiveRecord parameterized queries instead of interpolating user-supplied labels into raw SQL; use predicates such as LOWER(label) = ? with the downcased label.