296,853
Total vulnerabilities in the database
CKAN through 2.9.6 account takeovers by unauthenticated users when an existing user id is sent via an HTTP POST request. This allows a user to take over an existing account including superuser accounts.
| Software | From | Fixed in |
|---|---|---|
| okfn / ckan | - | 2.8.12 |
| okfn / ckan | 2.9.0 | 2.9.7 |
ckan
|
- | 2.9.7 |