SCA: security update for ckan (GHSA-2rqw-cfhc-35fh)

medium Tenable Cloud Security Plugin ID 409084

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- CKAN is an open-source data management system for powering data hubs and data portals. If there were
connection issues with the Solr server, the internal Solr URL (potentially including credentials) could be
leaked to package_search calls as part of the returned error message. This has been patched in CKAN 2.10.5
and 2.11.0. (CVE-2024-41674)

See Also

https://github.com/advisories/GHSA-2rqw-cfhc-35fh

Plugin Details

Severity: Medium

ID: 409084

Version: Revision 1.6

Type: Local

Family: SCA Checks

Published: 1/23/2025

Updated: 6/1/2026

Risk Information

VPR

Risk Factor: Low

Score: 1.4

Vendor

Vendor Severity: Medium

CVSS v2

Risk Factor: Medium

Base Score: 5

Temporal Score: 3.7

Vector: CVSS2#AV:N/AC:L/Au:N/C:P/I:N/A:N

CVSS Score Source: CVE-2024-41674

CVSS v3

Risk Factor: Medium

Base Score: 5.3

Temporal Score: 4.6

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

CVSS v4

Risk Factor: Medium

Base Score: 6.9

Threat Score: 2.7

Threat Vector: CVSS:4.0/E:U

Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N

Vulnerability Information

Exploit Ease: No known exploits are available

Patch Publication Date: 8/21/2024

Vulnerability Publication Date: 8/21/2024

Reference Information

CVE: CVE-2024-41674

cwe: CWE-209