Description


CKAN is an open-source data management system for powering data hubs and data portals. If there were connection issues with the Solr server, the internal Solr URL (potentially including credentials) could be leaked to package_search calls as part of the returned error message. This has been patched in CKAN 2.10.5 and 2.11.0.

Related CPE's


Vulnerable

Weaknesses



CWE-209


CWE-209

CVSS impact metrics


CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

5.3 · Medium

Information


Source identifier

[email protected]

Vulnerability status

Analyzed

Published

2024-08-21T13:15:08.770Z

1 year ago

Last modified

2024-08-23T15:06:58.063Z

1 year ago