CVE-2022-43685

Source
https://nvd.nist.gov/vuln/detail/CVE-2022-43685
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2022-43685.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2022-43685
Aliases
Published
2022-11-22T01:15:38Z
Modified
2025-07-01T14:19:14.203738Z
Severity
  • 8.8 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
[none]
Details

CKAN through 2.9.6 account takeovers by unauthenticated users when an existing user id is sent via an HTTP POST request. This allows a user to take over an existing account including superuser accounts.

References

Affected packages

Git / github.com/ckan/ckan

Affected ranges

Type
GIT
Repo
https://github.com/ckan/ckan
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed

Affected versions

ckan-1.*

ckan-1.3.3b
ckan-1.4
ckan-1.4.1
ckan-1.4.2
ckan-1.4.3
ckan-1.5
ckan-1.5.1
ckan-1.6
ckan-1.7

ckan-2.*

ckan-2.8.0
ckan-2.8.1
ckan-2.8.10
ckan-2.8.11
ckan-2.8.2
ckan-2.8.3
ckan-2.8.4
ckan-2.8.5
ckan-2.8.6
ckan-2.8.7
ckan-2.8.8
ckan-2.8.9

demo-0.*

demo-0.1
demo-0.2