Описание
CKAN is an open-source data management system for powering data hubs and data portals. Prior to versions 2.9.9 and 2.10.1, the ckan user (equivalent to www-data) owned code and configuration files in the docker container and the ckan user had the permissions to use sudo. These issues allowed for code execution or privilege escalation if an arbitrary file write bug was available. Versions 2.9.9, 2.9.9-dev, 2.10.1, and 2.10.1-dev contain a patch.
Ссылки
- Patch
- Vendor Advisory
- Patch
- Vendor Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 2.9.9 (исключая)
Одно из
cpe:2.3:a:okfn:ckan:*:*:*:*:*:*:*:*
cpe:2.3:a:okfn:ckan:2.10.0:*:*:*:*:*:*:*
EPSS
Процентиль: 43%
0.0021
Низкий
8.8 High
CVSS3
Дефекты
CWE-269
CWE-269
EPSS
Процентиль: 43%
0.0021
Низкий
8.8 High
CVSS3
Дефекты
CWE-269
CWE-269