MEDIUM 5.3 PyPI
CKAN may leak Solr credentials via error message in package_search action
GHSA-2rqw-cfhc-35fh · CVE-2024-41674 · PYSEC-2026-1248
Published · Modified
AI SAST
Find this class of vulnerability in your own code
Corgea's AI-native static analysis detects vulnerabilities like this one across your repositories, ranks them by exploitability, and returns review-ready fixes.
Description
If there were connection issues with the Solr server, the internal Solr URL (potentially including credentials) could be leaked to package_search calls as part of the returned error message
Patches
This has been patched in CKAN 2.10.5 and 2.11.0
Ready to move
Start Securing
Free, no credit card | First findings in minutes