Session Fixation Vulnerability in CKAN Data Management System
CVE-2025-64100

6.1MEDIUM

Key Information:

Vendor

Ckan

Status
Vendor
CVE Published:
29 October 2025

What is CVE-2025-64100?

The CKAN data management system is susceptible to session fixation, allowing an attacker to manipulate session identifiers when configured with server-side session storage. This flaw enables an attacker to either set a cookie in a target browser or hijack a valid session from a victim, potentially leading to unauthorized actions. The vulnerability is mitigated in CKAN versions 2.10.9 and 2.11.4 by introducing session regeneration after each login, enhancing user session security.

Affected Version(s)

ckan < 2.10.9 < 2.10.9

ckan >= 2.11.0, < 2.11.4 < 2.11.0, 2.11.4

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-64100 : Session Fixation Vulnerability in CKAN Data Management System