CKAN through 2.9.6 account takeovers by unauthenticated users when an existing user id is sent via an HTTP POST request. This allows a user to take over an existing account including superuser accounts.
References
Link Resource
https://ckan.org/ Vendor Advisory
https://ckan.org/blog/get-latest-patch-releases-your-ckan-site-october-2022 Release Notes Vendor Advisory
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: mitre

Published: 2022-11-22T00:00:00

Updated: 2022-11-22T00:00:00

Reserved: 2022-10-24T00:00:00


Link: CVE-2022-43685

JSON object: View

cve-icon NVD Information

Status : Analyzed

Published: 2022-11-22T01:15:38.730

Modified: 2023-08-08T14:21:49.707


Link: CVE-2022-43685

JSON object: View

cve-icon Redhat Information

No data.