CVE-2023-50248

    Dashboard / Vulnerabilities / CVE-2023-50248

    CVE-2023-50248

    Published: 13 Dec 2023Last Modified: 12 Aug 2026

    Summary: CKAN out of memory error when submitting the dataset form with a specially-crafted field

    Details: CKAN is an open-source data management system for powering data hubs and data portals. Starting in version 2.0.0 and prior to versions 2.9.10 and 2.10.3, when submitting a POST request to the `/dataset/new` endpoint (including either the auth cookie or the `Authorization` header) with a specially-crafted field, an attacker can create an out-of-memory error in the hosting server. To trigger this error, the attacker need to have permissions to create or edit datasets. This vulnerability has been patched in CKAN 2.10.3 and 2.9.10.

    Affected packages

    Package

    Name:

    Purl:

    Affected ranges

    Type: GIT

    Events:

    Introduced- aec8130bc07ffafd191c4192cca9de735c430dd1

    Affected versions

    ckan-2.10.2
    ckan-2.10.0

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High
    CVE-2023-50248 | CVE-DB