Skip to main content

Generation of Error Message Containing Sensitive Information

CVE-2024-41674

Severity Medium
Score 5.3/10

Summary

CKAN is an open-source data management system for powering data hubs and data portals. If there were connection issues with the Solr server, the internal Solr URL (potentially including credentials) could be leaked to "package_search" calls as part of the returned error message. This issue affects versions 2.0 through 2.10.4.

  • LOW
  • NETWORK
  • NONE
  • UNCHANGED
  • NONE
  • NONE
  • LOW
  • NONE

CWE-209 - Generation of Error Message Containing Sensitive Information

The software generates an error message that includes sensitive information about its environment, users, or associated data.

Advisory Timeline

  • Published