Description

CKAN is an open-source data management system for powering data hubs and data portals. The Datatables view plugin did not properly escape record data coming from the DataStore, leading to a potential XSS vector. Sites running CKAN >= 2.7.0 with the datatables_view plugin activated. This is a plugin included in CKAN core, that not activated by default but it is widely used to preview tabular data. This vulnerability has been fixed in CKAN 2.10.5 and 2.11.0.

INFO

Published Date :

2024-08-21T14:34:31.424Z

Last Modified :

2024-08-22T13:35:13.240Z

Source :

GitHub_M
AFFECTED PRODUCTS

The following products are affected by CVE-2024-41675 vulnerability.

Vendors Products
Okfn
  • Ckan

CVSS Vulnerability Scoring System

Detailed values of each vector for above chart.
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality Impact
Integrity Impact
Availability Impact