← Back

CVE-2024-41674

nvd nist
Published: Aug 21, 2024Modified: Jun 17, 2026

JSON object

Loading...
5.3
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Exploitability: 3.9 / Impact: 1.4
Source: NVD

Description

CKAN is an open-source data management system for powering data hubs and data portals. If there were connection issues with the Solr server, the internal Solr URL (potentially including credentials) could be leaked to package_search calls as part of the returned error message. This has been patched in CKAN 2.10.5 and 2.11.0.

Affected (1)

Products: Okfn: Ckan
1 product
Ckan
Configuration A
1 vulnerable
Vulnerable SoftwareAffected Versions
From 2.0 to 2.10.5

References (2)

Source: security-advisories@github.com
Vendor Advisory

Timeline

No history available yet.