Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-7fgc-89cx-w8j5

Опубликовано: 13 дек. 2023
Источник: github
Github: Прошло ревью
CVSS3: 4.5

Описание

Out of memory error when submitting the dataset form with a specially-crafted field

Impact

When submitting a POST request to the /dataset/new endpoint (including either the auth cookie or the Authorization header) with a specially-crafted field, an attacker can create an out-of-memory error in the hosting server.

To trigger this error the user needs to have permissions to create or edit datasets.

Patches

This vulnerability has been patched in CKAN 2.10.3 and 2.9.10

Пакеты

Наименование

ckan

pip
Затронутые версииВерсия исправления

>= 2.0, < 2.9.10

2.9.10

Наименование

ckan

pip
Затронутые версииВерсия исправления

>= 2.10.0, < 2.10.3

2.10.3

EPSS

Процентиль: 41%
0.00189
Низкий

4.5 Medium

CVSS3

Дефекты

CWE-130

Связанные уязвимости

CVSS3: 4.5
nvd
около 2 лет назад

CKAN is an open-source data management system for powering data hubs and data portals. Starting in version 2.0.0 and prior to versions 2.9.10 and 2.10.3, when submitting a POST request to the `/dataset/new` endpoint (including either the auth cookie or the `Authorization` header) with a specially-crafted field, an attacker can create an out-of-memory error in the hosting server. To trigger this error, the attacker need to have permissions to create or edit datasets. This vulnerability has been patched in CKAN 2.10.3 and 2.9.10.

EPSS

Процентиль: 41%
0.00189
Низкий

4.5 Medium

CVSS3

Дефекты

CWE-130