Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2024-41675

Опубликовано: 21 авг. 2024
Источник: nvd
CVSS3: 6.8
CVSS3: 6.1
EPSS Низкий

Описание

CKAN is an open-source data management system for powering data hubs and data portals. The Datatables view plugin did not properly escape record data coming from the DataStore, leading to a potential XSS vector. Sites running CKAN >= 2.7.0 with the datatables_view plugin activated. This is a plugin included in CKAN core, that not activated by default but it is widely used to preview tabular data. This vulnerability has been fixed in CKAN 2.10.5 and 2.11.0.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:okfn:ckan:*:*:*:*:*:*:*:*
Версия от 2.7.0 (включая) до 2.10.5 (исключая)

EPSS

Процентиль: 77%
0.01078
Низкий

6.8 Medium

CVSS3

6.1 Medium

CVSS3

Дефекты

CWE-79
CWE-79

Связанные уязвимости

CVSS3: 6.8
github
больше 1 года назад

CKAN has Cross-site Scripting vector in the Datatables view plugin

EPSS

Процентиль: 77%
0.01078
Низкий

6.8 Medium

CVSS3

6.1 Medium

CVSS3

Дефекты

CWE-79
CWE-79