Impact
CKAN MCP Server allows callers to receive unfiltered upstream response bodies when contacting non‑CKAN hosts, or to see internal exception information if an error occurs. The raw data can include hostnames, internal IP addresses, database errors, and stack fragments, which can give an attacker insight into system internals and potential attack vectors. The vulnerability is identified as a moderate‑severity information‑disclosure flaw with a CVSS score of 3.7.
Affected Systems
Vendors affected are Ondata CKAN MCP Server versions prior to 0.4.112. The issue exists in all builds before that release; upgrading to 0.4.112 or later removes the vulnerability.
Risk and Exploitability
The CVSS score indicates a low to moderate risk. EPSS is not available, and the flaw is not listed in the CISA KEV catalog, meaning it has not yet been reported as a widely exploited vulnerability. The most likely attack vector involves directing the server to a malicious host via direct input, redirection, or SSFR. Because the server echoes the upstream content verbatim, an attacker with the ability to influence the query can glean internal details without additional privileges.
OpenCVE Enrichment