PT-2023-18682 · Ckan · Ckan

Publicado

2023-02-03

·

Atualizado

2023-02-14

·

CVE-2023-22746

CVSS v3.1

8.6

Alta

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:L
Name of the Vulnerable Software and Affected Versions CKAN versions (affected versions not specified)
Description The issue concerns CKAN, an open-source data management system, where a default secret key is used across different instances when creating new containers based on specific Docker images. This allows for easy forgery of authentication requests if users do not set a custom secret key via environment variables in the .env file. The affected images include ckan/ckan-docker, ckan/ckan-base, okfn/docker-ckan, openknowledge/ckan-base, openknowledge/ckan-dev, keitaroinc/docker-ckan, and keitaro/ckan images.
Recommendations For all affected versions, set a custom secret key via environment variables in the .env file to prevent the use of the default shared secret key. As a temporary workaround, consider overriding the default secret key in your own .env file until a more permanent solution is implemented. Restrict access to authentication endpoints to minimize the risk of exploitation.

Exploit

Correção

Use of Insufficiently Random Values

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2023-22746
GHSA-PR8J-V4C8-H62X

Produtos afetados

Ckan