Lucene search

K
nvd[email protected]NVD:CVE-2023-50248
HistoryDec 13, 2023 - 9:15 p.m.

CVE-2023-50248

2023-12-1321:15:08
CWE-130
web.nvd.nist.gov
2
ckan
data management
out-of-memory error
vulnerability
post request
authorization header
patch
cve-2023-50248

CVSS3

6.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

EPSS

0

Percentile

13.3%

CKAN is an open-source data management system for powering data hubs and data portals. Starting in version 2.0.0 and prior to versions 2.9.10 and 2.10.3, when submitting a POST request to the /dataset/new endpoint (including either the auth cookie or the Authorization header) with a specially-crafted field, an attacker can create an out-of-memory error in the hosting server. To trigger this error, the attacker need to have permissions to create or edit datasets. This vulnerability has been patched in CKAN 2.10.3 and 2.9.10.

Affected configurations

Nvd
Node
okfnckanRange2.02.9.10
OR
okfnckanRange2.10.02.10.3
VendorProductVersionCPE
okfnckan*cpe:2.3:a:okfn:ckan:*:*:*:*:*:*:*:*

CVSS3

6.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

EPSS

0

Percentile

13.3%

Related for NVD:CVE-2023-50248