GHSA-6w9p-88qg-p3g3
Dashboard / Vulnerabilities / GHSA-6w9p-88qg-p3g3
GHSA-6w9p-88qg-p3g3
Summary: Cross-site Scripting in CKAN
Details: In CKAN, versions 2.9.0 to 2.9.3 are affected by a stored XSS vulnerability via SVG file upload of users’ profile picture. This allows low privileged application users to store malicious scripts in their profile picture. These scripts are executed in a victim’s browser when they open the malicious profile picture
References: https://nvd.nist.gov/vuln/detail/CVE-2021-25967, https://github.com/ckan/ckan/pull/6477, https://github.com/ckan/ckan/commit/5a46989c0a4f2c2873ca182c196da83b82babd25, https://github.com/advisories/GHSA-6w9p-88qg-p3g3, https://github.com/ckan/ckan, https://github.com/pypa/advisory-database/tree/main/vulns/ckan/PYSEC-2021-841.yaml, https://www.whitesourcesoftware.com/vulnerability-database/CVE-2021-25967
Affected packages
Package
Name: ckan
Purl: pkg:pypi/ckan
Affected ranges
Type: ECOSYSTEM
Events:
