Vulnerability record · CVE-2022-43685 · published 22 November 2022
CVE-2022-43685: Okfn ckan missing authorization vulnerability
Okfn · Ckan
CKAN through 2.9.6 account takeovers by unauthenticated users when an existing user id is sent via an HTTP POST request. This allows a user to take over an existing account including superuser accounts.
Description
CKAN through 2.9.6 account takeovers by unauthenticated users when an existing user id is sent via an HTTP POST request. This allows a user to take over an existing account including superuser accounts.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://ckan.org/ | Vendor Advisory |
| https://ckan.org/blog/get-latest-patch-releases-your-ckan-site-october-2022 | Release NotesVendor Advisory |
| https://ckan.org/ | Vendor Advisory |
| https://ckan.org/blog/get-latest-patch-releases-your-ckan-site-october-2022 | Release NotesVendor Advisory |
Track CVE-2022-43685 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2022-43685), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.