CVE Feed

    Dashboard / CVE / CVE-2024-41674

    CVE-2024-41674

    CKAN is an open-source data management system for powering data hubs and data portals. If there were connection issues with the Solr server, the internal Solr URL (potentially including credentials) could be leaked to package_search calls as part of the returned error message. This has been patched in CKAN 2.10.5 and 2.11.0.

    Published:Aug 21, 2024
    Last Modified:Aug 23, 2024
    EPS:Aug 21, 2024
    EPSS Score:0.00153
    CVSS Score:5.3

    Affected Products

    Vendor
    Ckan
    Product
    Ckan
    Vendor
    Okfn
    Product
    Ckan

    Exploits

    No exploit reference

    Related CVEs

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High