PT-2025-44311 · Ckan · Ckan
Published
2025-10-29
·
Updated
2025-10-29
·
CVE-2025-54384
CVSS v3.1
6.3
Medium
| Vector | AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
CKAN versions prior to 2.10.9
CKAN versions prior to 2.11.4
Description
CKAN, an open-source data management system, contains a flaw in the
helpers.markdown extract() function. Insufficient input sanitization before wrapping data in an HTML literal element can lead to a potential cross-site scripting (XSS) vector. This impacts the rendering of user-provided data on dataset, resource, organization, or group pages, as well as pages provided by extensions utilizing this helper function.Recommendations
Update to CKAN version 2.10.9 or later.
Update to CKAN version 2.11.4 or later.
Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Ckan