Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-r3jc-vhf4-6v32

Опубликовано: 21 авг. 2024
Источник: github
Github: Прошло ревью
CVSS4: 6.1
CVSS3: 6.8

Описание

CKAN has Cross-site Scripting vector in the Datatables view plugin

The Datatables view plugin did not properly escape record data coming from the DataStore, leading to a potential XSS vector.

Impact

Sites running CKAN >= 2.7.0 with the datatables_view plugin activated. This is a plugin included in CKAN core, that not activated by default but it is widely used to preview tabular data.

Patches

This vulnerability has been fixed in CKAN 2.10.5 and 2.11.0

Workarounds

Prevent importing of tabular files to the DataStore via DataPusher, XLoader,etc, at least those published from untrusted sources.

Пакеты

Наименование

ckan

pip
Затронутые версииВерсия исправления

>= 2.7.0, < 2.10.5

2.10.5

EPSS

Процентиль: 77%
0.01078
Низкий

6.1 Medium

CVSS4

6.8 Medium

CVSS3

Дефекты

CWE-79

Связанные уязвимости

CVSS3: 6.8
nvd
больше 1 года назад

CKAN is an open-source data management system for powering data hubs and data portals. The Datatables view plugin did not properly escape record data coming from the DataStore, leading to a potential XSS vector. Sites running CKAN >= 2.7.0 with the datatables_view plugin activated. This is a plugin included in CKAN core, that not activated by default but it is widely used to preview tabular data. This vulnerability has been fixed in CKAN 2.10.5 and 2.11.0.

EPSS

Процентиль: 77%
0.01078
Низкий

6.1 Medium

CVSS4

6.8 Medium

CVSS3

Дефекты

CWE-79