Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
By Recent Activity
okfn ckan vulnerabilities and exploits
(subscribe to this query)
9.8
CVE-2023-32321
CKAN is an open-source data management system for powering data hubs and data portals. Multiple vulnerabilities have been discovered in Ckan which may lead to remote code execution. An arbitrary file write in `resource_create` and `package_update` actions, using the...
Okfn Ckan
Okfn Ckan 2.10.0
8.8
CVE-2023-32696
CKAN is an open-source data management system for powering data hubs and data portals. Prior to versions 2.9.9 and 2.10.1, the `ckan` user (equivalent to www-data) owned code and configuration files in the docker container and the `ckan` user had the permissions to use sudo....
Okfn Ckan 2.10.0
Okfn Ckan
8.8
CVE-2022-43685
CKAN through 2.9.6 account takeovers by unauthenticated users when an existing user id is sent via an HTTP POST request. This allows a user to take over an existing account including superuser accounts....
Okfn Ckan
7.5
CVE-2023-22746
CKAN is an open-source DMS (data management system) for powering data hubs and data portals. When creating a new container based on one of the Docker images listed below, the same secret key was being used by default. If the users didn't set a custom value via environment...
Okfn Ckan
5.4
CVSSv3
CVE-2021-25967
In CKAN, versions 2.9.0 to 2.9.3 are affected by a stored XSS vulnerability via SVG file upload of users’ profile picture. This allows low privileged application users to store malicious scripts in their profile picture. These scripts are executed in a victim’s...
Okfn Ckan
CVSSv3
CVSSv2
CVSSv3
VMScore
Recommendations:
brute force
log injection
CVE-2023-6510
CVE-2023-49248
CVE-2023-49374
CVE-2023-26360
XSS
CVE-2023-46674
CVE-2023-49105
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started