PT-2023-31506 · Ckan · Ckan

Thorge

·

Published

2023-12-13

·

Updated

2023-12-18

·

CVE-2023-50248

CVSS v3.1

4.5

Medium

VectorAV:N/AC:L/PR:H/UI:R/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions CKAN versions 2.0.0 through 2.9.9 CKAN versions 2.10.0 through 2.10.2
Description CKAN is an open-source data management system for powering data hubs and data portals. When submitting a POST request to the "/dataset/new" endpoint (including either the auth cookie or the Authorization header) with a specially-crafted field, an attacker can create an out-of-memory error in the hosting server. To trigger this error, the attacker needs to have permissions to create or edit datasets.
Recommendations For CKAN versions 2.0.0 through 2.9.9, update to version 2.9.10 or later. For CKAN versions 2.10.0 through 2.10.2, update to version 2.10.3 or later. As a temporary workaround, consider restricting access to the "/dataset/new" endpoint for users with permissions to create or edit datasets until a patch is applied.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2023-50248
GHSA-7FGC-89CX-W8J5

Affected Products

Ckan