GHSA-7pq5-qcp6-mcww

Suggest an improvement
Source
https://github.com/advisories/GHSA-7pq5-qcp6-mcww
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2025/02/GHSA-7pq5-qcp6-mcww/GHSA-7pq5-qcp6-mcww.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-7pq5-qcp6-mcww
Aliases
Published
2025-02-05T17:41:33Z
Modified
2026-07-07T17:56:58Z
Severity
  • 7.3 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:N CVSS Calculator
Summary
CKAN has an XSS vector in user uploaded images in group/org and user profiles
Details

Impact

Using a specially crafted file, a user could potentially upload a file containing code that when executed could send arbitrary requests to the server. If that file was opened by an administrator, it could lead to escalation of privileges of the original submitter or other malicious actions. Users must have been registered to the site to exploit this vulnerability.

Patches

This vulnerability has been fixed in CKAN 2.10.7 and 2.11.2

Workarounds

On versions prior to CKAN 2.10.7 and 2.11.2, site maintainers can restrict the file types supported for uploading using the ckan.upload.user.mimetypes / ckan.upload.user.types and ckan.upload.group.mimetypes / ckan.upload.group.types config options. To entirely disable file uploads you can use:

ckan.upload.user.types = none
Database specific
{
    "cwe_ids":  [
        "CWE-79"
    ],
    "github_reviewed":  true,
    "github_reviewed_at":  "2025-02-05T17:41:33Z",
    "nvd_published_at":  "2025-02-05T19:15:46Z",
    "severity":  "HIGH"
}
References

Affected packages

PyPI / ckan

Package

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
2.10.7

Affected versions

0.*
0.3
0.4
0.5
0.6
0.7
0.8
0.11
1.*
1.0
1.1
1.2
1.3
1.3.2
1.3.3
1.4
1.4.1
1.4.2
1.4.3
1.4.3.1
1.5
1.5.1
1.6
1.7
1.7.1
1.8
2.*
2.0
2.0.1
2.0.7
2.0.8
2.1
2.1.1
2.1.5
2.1.6
2.2
2.2.1
2.2.3
2.2.4
2.3
2.3.1
2.3.2
2.3.3
2.3.4
2.3.5
2.4.0
2.4.1
2.4.2
2.4.3
2.4.4
2.4.5
2.4.8
2.4.9
2.5.0
2.5.1
2.5.2
2.5.3
2.5.4
2.5.6
2.5.7
2.5.8
2.5.9
2.6.0
2.6.1
2.6.3
2.6.4
2.6.5
2.6.6
2.6.7
2.6.8
2.6.9
2.7.0
2.7.1
2.7.2
2.7.3
2.7.4
2.7.5
2.7.6
2.7.7
2.7.8
2.7.9
2.7.10
2.7.11
2.7.12
2.8.0
2.8.1
2.8.2
2.8.3
2.8.4
2.8.5
2.8.6
2.8.7
2.8.8
2.8.9
2.8.10
2.8.11
2.8.12
2.9.0
2.9.1
2.9.2
2.9.3
2.9.4
2.9.5
2.9.6
2.9.7
2.9.8
2.9.9
2.9.10
2.9.11
2.10.0
2.10.1
2.10.3
2.10.4
2.10.5
2.10.6

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2025/02/GHSA-7pq5-qcp6-mcww/GHSA-7pq5-qcp6-mcww.json"

PyPI / ckan

Package

Affected ranges

Type
ECOSYSTEM
Events
Introduced
2.11.0
Fixed
2.11.2

Affected versions

2.*
2.11.0
2.11.1

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2025/02/GHSA-7pq5-qcp6-mcww/GHSA-7pq5-qcp6-mcww.json"