PT-2023-31506 · Ckan · Ckan

Thorge

·

Publicado

2023-12-13

·

Atualizado

2023-12-18

·

CVE-2023-50248

CVSS v3.1

4.5

Média

VetorAV:N/AC:L/PR:H/UI:R/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions CKAN versions 2.0.0 through 2.9.9 CKAN versions 2.10.0 through 2.10.2
Description CKAN is an open-source data management system for powering data hubs and data portals. When submitting a POST request to the "/dataset/new" endpoint (including either the auth cookie or the Authorization header) with a specially-crafted field, an attacker can create an out-of-memory error in the hosting server. To trigger this error, the attacker needs to have permissions to create or edit datasets.
Recommendations For CKAN versions 2.0.0 through 2.9.9, update to version 2.9.10 or later. For CKAN versions 2.10.0 through 2.10.2, update to version 2.10.3 or later. As a temporary workaround, consider restricting access to the "/dataset/new" endpoint for users with permissions to create or edit datasets until a patch is applied.

Exploit

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2023-50248
GHSA-7FGC-89CX-W8J5

Produtos afetados

Ckan