Okfn

Ckan

14 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.12%
  • Veröffentlicht 13.05.2026 19:17:22
  • Zuletzt bearbeitet 15.05.2026 14:58:38

CKAN is an open-source DMS (data management system) for powering data hubs and data portals. Prior to 2.10.10 and 2.11.5, Access to the views via tokens or unauthenticated requests marked the endpoint as not requiring CSRF protection. The marking was...

  • EPSS 1.82%
  • Veröffentlicht 13.05.2026 19:17:22
  • Zuletzt bearbeitet 15.05.2026 14:59:11

CKAN is an open-source DMS (data management system) for powering data hubs and data portals. Prior to 2.10.10 and 2.11.5, a vulnerability in datastore_search_sql allowed attackers to inject SQL in order to gain access to private resources and Postgre...

  • EPSS 0.37%
  • Veröffentlicht 13.05.2026 19:17:22
  • Zuletzt bearbeitet 15.05.2026 15:02:11

CKAN is an open-source DMS (data management system) for powering data hubs and data portals. Prior to 2.10.10 and 2.11.5, a vulnerability in datastore_search_sql allowed attackers to bypass authorization in order to gain access to private resources a...

  • EPSS 0.19%
  • Veröffentlicht 13.05.2026 19:17:21
  • Zuletzt bearbeitet 15.05.2026 14:57:57

CKAN is an open-source DMS (data management system) for powering data hubs and data portals. Prior to 2.10.10 and 2.11.5, the configured SMTP server may be spoofed with any certificate (e.g. self-signed), leaving credentials and all emails sent open ...

  • EPSS 0.35%
  • Veröffentlicht 21.08.2024 15:15:09
  • Zuletzt bearbeitet 23.08.2024 16:20:10

CKAN is an open-source data management system for powering data hubs and data portals. There are a number of CKAN plugins, including XLoader, DataPusher, Resource proxy and ckanext-archiver, that work by downloading the contents of local or remote fi...

  • EPSS 0.38%
  • Veröffentlicht 21.08.2024 15:15:08
  • Zuletzt bearbeitet 23.08.2024 17:06:58

CKAN is an open-source data management system for powering data hubs and data portals. If there were connection issues with the Solr server, the internal Solr URL (potentially including credentials) could be leaked to package_search calls as part of ...

  • EPSS 0.38%
  • Veröffentlicht 21.08.2024 15:15:08
  • Zuletzt bearbeitet 23.08.2024 17:07:28

CKAN is an open-source data management system for powering data hubs and data portals. The Datatables view plugin did not properly escape record data coming from the DataStore, leading to a potential XSS vector. Sites running CKAN >= 2.7.0 with the d...

  • EPSS 0.43%
  • Veröffentlicht 13.03.2024 21:15:58
  • Zuletzt bearbeitet 23.01.2025 21:22:17

A user endpoint didn't perform filtering on an incoming parameter, which was added directly to the application log. This could lead to an attacker injecting false log entries or corrupt the log file format. This has been fixed in the CKAN versions 2....

  • EPSS 0.58%
  • Veröffentlicht 13.12.2023 21:15:08
  • Zuletzt bearbeitet 21.11.2024 08:36:44

CKAN is an open-source data management system for powering data hubs and data portals. Starting in version 2.0.0 and prior to versions 2.9.10 and 2.10.3, when submitting a POST request to the `/dataset/new` endpoint (including either the auth cookie ...

  • EPSS 0.79%
  • Veröffentlicht 30.05.2023 19:15:10
  • Zuletzt bearbeitet 21.11.2024 08:03:52

CKAN is an open-source data management system for powering data hubs and data portals. Prior to versions 2.9.9 and 2.10.1, the `ckan` user (equivalent to www-data) owned code and configuration files in the docker container and the `ckan` user had the...