CKAN is an open-source data management system for powering data hubs and data portals. If there were connection issues with the Solr server, the internal Solr URL (potentially including credentials) could be leaked to package_search calls as part of the returned error message. This has been patched in CKAN 2.10.5 and 2.11.0.
                
            Metrics
Affected Vendors & Products
Advisories
    | Source | ID | Title | 
|---|---|---|
|  EUVD | EUVD-2024-2468 | CKAN is an open-source data management system for powering data hubs and data portals. If there were connection issues with the Solr server, the internal Solr URL (potentially including credentials) could be leaked to package_search calls as part of the returned error message. This has been patched in CKAN 2.10.5 and 2.11.0. | 
|  Github GHSA | GHSA-2rqw-cfhc-35fh | CKAN may leak Solr credentials via error message in package_search action | 
Fixes
    Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
        History
                    Fri, 23 Aug 2024 17:30:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| First Time appeared | Okfn Okfn ckan | |
| CPEs | cpe:2.3:a:okfn:ckan:*:*:*:*:*:*:*:* | |
| Vendors & Products | Okfn Okfn ckan | 
Wed, 21 Aug 2024 16:30:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| First Time appeared | Ckan Ckan ckan | |
| CPEs | cpe:2.3:a:ckan:ckan:*:*:*:*:*:*:*:* | |
| Vendors & Products | Ckan Ckan ckan | |
| Metrics | ssvc 
 | 
Wed, 21 Aug 2024 14:45:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| Description | CKAN is an open-source data management system for powering data hubs and data portals. If there were connection issues with the Solr server, the internal Solr URL (potentially including credentials) could be leaked to package_search calls as part of the returned error message. This has been patched in CKAN 2.10.5 and 2.11.0. | |
| Title | CKAN may leak Solr credentials via error message in package_search action | |
| Weaknesses | CWE-209 | |
| References |  | |
| Metrics | cvssV3_1 
 | 
 MITRE
                        MITRE
                    Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2024-08-21T15:32:22.705Z
Reserved: 2024-07-18T15:21:47.486Z
Link: CVE-2024-41674
 Vulnrichment
                        Vulnrichment
                    Updated: 2024-08-21T15:32:08.866Z
 NVD
                        NVD
                    Status : Analyzed
Published: 2024-08-21T15:15:08.770
Modified: 2024-08-23T17:06:58.063
Link: CVE-2024-41674
 Redhat
                        Redhat
                    No data.
 OpenCVE Enrichment
                        OpenCVE Enrichment
                    No data.