Junglewise Threat Intelligence

CVE-2024-41674: PYSEC-2026-1248 - CKAN may leak Solr credentials via error message in package_search action

CVE-2024-41674 · Severity: low · CVSS 3.1 · Published 2026-07-07

Technologies: CKAN Project CKAN, ckan (PyPI). Vendors: PyPI.

Executive brief

CKAN is an open data management platform that uses Solr as a search backend. When the Solr server is unreachable or experiences connection problems, CKAN's package_search API may leak the internal Solr URL including authentication credentials in error messages returned to callers. This could allow attackers to obtain database credentials and potentially compromise the underlying search infrastructure.

Technical details

The vulnerability is a case of sensitive information disclosure (CWE-209) where error handling in the package_search action fails to sanitize exception messages. When Solr connection failures occur, the raw Solr URL containing embedded credentials is included in the error response without filtering. The attack requires network access to the package_search API endpoint with no authentication required; an attacker can trigger connection errors by calling the API during Solr downtime or network issues. The vulnerability has been patched in CKAN 2.10.5 and 2.11.0.

Affected products

  • CKAN Project CKAN 2.0.0 through 2.10.4, excluding 2.10.5 and 2.11.0

Timeline

  • 2024-08-21: disclosed
  • 2024-08-21: patched: Patched in CKAN 2.10.5 and 2.11.0

References

Related threats