PT-2023-31506 · Ckan · Ckan
Thorge
·
Published
2023-12-13
·
Updated
2023-12-18
·
CVE-2023-50248
CVSS v3.1
4.5
Medium
| Vector | AV:N/AC:L/PR:H/UI:R/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
CKAN versions 2.0.0 through 2.9.9
CKAN versions 2.10.0 through 2.10.2
Description
CKAN is an open-source data management system for powering data hubs and data portals. When submitting a POST request to the "/dataset/new" endpoint (including either the auth cookie or the
Authorization header) with a specially-crafted field, an attacker can create an out-of-memory error in the hosting server. To trigger this error, the attacker needs to have permissions to create or edit datasets.Recommendations
For CKAN versions 2.0.0 through 2.9.9, update to version 2.9.10 or later.
For CKAN versions 2.10.0 through 2.10.2, update to version 2.10.3 or later.
As a temporary workaround, consider restricting access to the "/dataset/new" endpoint for users with permissions to create or edit datasets until a patch is applied.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Ckan