Executive brief
CKAN is an open data management platform that uses Solr as a search backend. When the Solr server is unreachable or experiences connection problems, CKAN's package_search API may leak the internal Solr URL including authentication credentials in error messages returned to callers. This could allow attackers to obtain database credentials and potentially compromise the underlying search infrastructure.
Technical details
The vulnerability is a case of sensitive information disclosure (CWE-209) where error handling in the package_search action fails to sanitize exception messages. When Solr connection failures occur, the raw Solr URL containing embedded credentials is included in the error response without filtering. The attack requires network access to the package_search API endpoint with no authentication required; an attacker can trigger connection errors by calling the API during Solr downtime or network issues. The vulnerability has been patched in CKAN 2.10.5 and 2.11.0.
Affected products
- CKAN Project CKAN 2.0.0 through 2.10.4, excluding 2.10.5 and 2.11.0
Timeline
- 2024-08-21: disclosed
- 2024-08-21: patched: Patched in CKAN 2.10.5 and 2.11.0