PT-2023-18682 · Ckan · Ckan

CVE-2023-22746

·

Publicado

2023-02-03

·

Atualizado

2023-02-14

CVSS v3.1

8.6

Alta

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:L
Name of the Vulnerable Software and Affected Versions CKAN versions (affected versions not specified)
Description The issue concerns CKAN, an open-source data management system, where a default secret key is used across different instances when creating new containers based on specific Docker images. This allows for easy forgery of authentication requests if users do not set a custom secret key via environment variables in the .env file. The affected images include ckan/ckan-docker, ckan/ckan-base, okfn/docker-ckan, openknowledge/ckan-base, openknowledge/ckan-dev, keitaroinc/docker-ckan, and keitaro/ckan images.
Recommendations For all affected versions, set a custom secret key via environment variables in the .env file to prevent the use of the default shared secret key. As a temporary workaround, consider overriding the default secret key in your own .env file until a more permanent solution is implemented. Restrict access to authentication endpoints to minimize the risk of exploitation.

Exploit

Correção

DoS

Use of Insufficiently Random Values

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2023-22746
GHSA-PR8J-V4C8-H62X

Produtos afetados

Ckan