Back to CVE List

CVE-2026-42032

MEDIUM SEVERITY

CVSS Score & Metrics

Base Score
9.1 / 10
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N

Vulnerability Description

CKAN is an open-source DMS (data management system) for powering data hubs and data portals. Prior to 2.10.10 and 2.11.5, a vulnerability in datastore_search_sql allowed attackers to bypass authorization in order to gain access to private resources and PostgreSQL system information This vulnerability is fixed in 2.10.10 and 2.11.5.

Vulnerability Details

Published Date
Last Modified
CWE ID
CWE-863
Source
GitHub
Vendor
pip
Product
ckan

External References

Discussion (0)

Add Comment

No comments yet. Be the first!