CVE-2024-41675 Details
Description
CKAN is an open-source data management system for powering data hubs and data portals. The Datatables view plugin did not properly escape record data coming from the DataStore, leading to a potential XSS vector. Sites running CKAN >= 2.7.0 with the datatables_view plugin activated. This is a plugin included in CKAN core, that not activated by default but it is widely used to preview tabular data. This vulnerability has been fixed in CKAN 2.10.5 and 2.11.0.
A cross-site scripting (XSS) vulnerability has been identified in the CKAN open-source data management system, specifically within the Datatables view plugin. This issue affects CKAN versions 2.7.0 and later, where the plugin is activated. The vulnerability arises because the Datatables view plugin did not properly escape record data retrieved from the DataStore, creating a potential XSS vector. The Datatables view plugin is included in CKAN core but is not activated by default. However, it is widely used to preview tabular data.
Users can upgrade to CKAN versions 2.10.5 or 2.11.0, where this vulnerability has been fixed. Additionally, as a temporary workaround, avoid importing tabular files from untrusted sources into the DataStore.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Aug 22, 2024References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-79 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | [email protected] |
| CWE-79 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| okfn ckan | >= 2.7.0, < 2.10.5 |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Aug 23, 2024 | Initial Analysis | [email protected] |
| Aug 21, 2024 | New CVE Received | [email protected] |