MEDIUM 5.3 PyPI
CKAN may leak Solr credentials via error message in package_search action
GHSA-2rqw-cfhc-35fh · CVE-2024-41674
Published · Modified
Description
If there were connection issues with the Solr server, the internal Solr URL (potentially including credentials) could be leaked to package_search calls as part of the returned error message
Patches
This has been patched in CKAN 2.10.5 and 2.11.0
Ready to move
Start Securing
Free, no credit card | First findings in minutes