MEDIUM 5.3 PyPI

CKAN may leak Solr credentials via error message in package_search action

GHSA-2rqw-cfhc-35fh · CVE-2024-41674

Published · Modified

Description

If there were connection issues with the Solr server, the internal Solr URL (potentially including credentials) could be leaked to package_search calls as part of the returned error message

Patches

This has been patched in CKAN 2.10.5 and 2.11.0

Ready to move

Start Securing

Free, no credit card | First findings in minutes