CVE-2024-41674

MEDIUM

Okfn Ckan < 2.10.5 - Error Information Exposure

Title source: rule
STIX 2.1

Description

CKAN is an open-source data management system for powering data hubs and data portals. If there were connection issues with the Solr server, the internal Solr URL (potentially including credentials) could be leaked to package_search calls as part of the returned error message. This has been patched in CKAN 2.10.5 and 2.11.0.

Scores

CVSS v3 5.3
EPSS 0.0047
EPSS Percentile 64.9%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact partial

Details

CWE
CWE-209
Status published
Products (2)
okfn/ckan 2.0 - 2.10.5
pypi/ckan 2.0.0 - 2.10.5PyPI
Published Aug 21, 2024
Tracked Since Feb 18, 2026