REDHAT-BUG-2544601: Medium severity Pulp Pulp Container Plugin vulnerability
RegistryAuthHttpDownloader.registryauth is a class attribute (pulpcontainer/app/downloaders.py). Every instance in the worker shares one basic-auth value and one bearer token. A later download in that process, including another remote, task, or domain, sends the Authorization header stored by an earlier authenticated sync. Remote username, password, and clientkey are write-only on the API, so the syncing account cannot read them back. The caller obtains them by pointing a remote they can sync at a server they control. Introduced in dbef26e7, first release 1.3.0. This is a separate CVE from the pulp-ansible token cache: different repository, independently fixable.
Affected Software
Event History
Frequently Asked Questions
What deployment scope can be affected by the shared authentication state?
Authentication state is shared by every RegistryAuthHttpDownloader instance within a worker process. A later download can therefore use credentials or a bearer token from an earlier authenticated sync, including across different remotes, tasks, or domains handled by that process.
What access would an attacker need to obtain leaked credentials?
The attacker needs to be able to point a remote they can sync at a server they control. They can then obtain the Authorization header sent by a later download that reuses authentication state from an earlier authenticated sync in the same worker.
Does the API's write-only handling of remote secrets prevent disclosure?
No. Remote usernames, passwords, and client keys cannot be read back through the API, but the issue can expose the resulting basic-auth value or bearer token through an outbound Authorization header.
Which releases are identified as affected?
The issue was introduced in commit dbef26e7 and was first released in version 1.3.0. The provided data does not identify a fixed version.