CVE-2024-43371
- EPSS 0.32%
- Veröffentlicht 21.08.2024 15:15:09
- Zuletzt bearbeitet 23.08.2024 16:20:10
CKAN is an open-source data management system for powering data hubs and data portals. There are a number of CKAN plugins, including XLoader, DataPusher, Resource proxy and ckanext-archiver, that work by downloading the contents of local or remote fi...
CVE-2024-41674
- EPSS 0.48%
- Veröffentlicht 21.08.2024 15:15:08
- Zuletzt bearbeitet 23.08.2024 17:06:58
CKAN is an open-source data management system for powering data hubs and data portals. If there were connection issues with the Solr server, the internal Solr URL (potentially including credentials) could be leaked to package_search calls as part of ...
CVE-2024-41675
- EPSS 1.08%
- Veröffentlicht 21.08.2024 15:15:08
- Zuletzt bearbeitet 23.08.2024 17:07:28
CKAN is an open-source data management system for powering data hubs and data portals. The Datatables view plugin did not properly escape record data coming from the DataStore, leading to a potential XSS vector. Sites running CKAN >= 2.7.0 with the d...
CVE-2024-27097
- EPSS 0.34%
- Veröffentlicht 13.03.2024 21:15:58
- Zuletzt bearbeitet 23.01.2025 21:22:17
A user endpoint didn't perform filtering on an incoming parameter, which was added directly to the application log. This could lead to an attacker injecting false log entries or corrupt the log file format. This has been fixed in the CKAN versions 2....
CVE-2023-50248
- EPSS 0.18%
- Veröffentlicht 13.12.2023 21:15:08
- Zuletzt bearbeitet 21.11.2024 08:36:44
CKAN is an open-source data management system for powering data hubs and data portals. Starting in version 2.0.0 and prior to versions 2.9.10 and 2.10.3, when submitting a POST request to the `/dataset/new` endpoint (including either the auth cookie ...
CVE-2023-32696
- EPSS 0.28%
- Veröffentlicht 30.05.2023 19:15:10
- Zuletzt bearbeitet 21.11.2024 08:03:52
CKAN is an open-source data management system for powering data hubs and data portals. Prior to versions 2.9.9 and 2.10.1, the `ckan` user (equivalent to www-data) owned code and configuration files in the docker container and the `ckan` user had the...
CVE-2023-32321
- EPSS 3.79%
- Veröffentlicht 26.05.2023 23:15:18
- Zuletzt bearbeitet 21.11.2024 08:03:06
CKAN is an open-source data management system for powering data hubs and data portals. Multiple vulnerabilities have been discovered in Ckan which may lead to remote code execution. An arbitrary file write in `resource_create` and `package_update` ac...
CVE-2023-22746
- EPSS 0.37%
- Veröffentlicht 03.02.2023 22:15:11
- Zuletzt bearbeitet 21.11.2024 07:45:20
CKAN is an open-source DMS (data management system) for powering data hubs and data portals. When creating a new container based on one of the Docker images listed below, the same secret key was being used by default. If the users didn't set a custom...
CVE-2022-43685
- EPSS 0.86%
- Veröffentlicht 22.11.2022 01:15:38
- Zuletzt bearbeitet 29.04.2025 05:15:45
CKAN through 2.9.6 account takeovers by unauthenticated users when an existing user id is sent via an HTTP POST request. This allows a user to take over an existing account including superuser accounts.
CVE-2021-25967
- EPSS 0.21%
- Veröffentlicht 01.12.2021 14:15:07
- Zuletzt bearbeitet 21.11.2024 05:55:41
In CKAN, versions 2.9.0 to 2.9.3 are affected by a stored XSS vulnerability via SVG file upload of users’ profile picture. This allows low privileged application users to store malicious scripts in their profile picture. These scripts are executed in...