CKAN patches Solr server leak to prevent potential security risk
CVE-2024-41674
5.3MEDIUM
Key Information
- Vendor
- Ckan
- Status
- Ckan
- Vendor
- CVE Published:
- 21 August 2024
Summary
CKAN is an open-source data management system for powering data hubs and data portals. If there were connection issues with the Solr server, the internal Solr URL (potentially including credentials) could be leaked to package_search calls as part of the returned error message. This has been patched in CKAN 2.10.5 and 2.11.0.
Affected Version(s)
ckan = >= 2.0, < 2.10.5
CVSS V3.1
Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published.
Vulnerability Reserved.
Collectors
NVD DatabaseMitre Database