Vulnerabilities (CVE)

Filtered by vendor Okfn Subscribe
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2022-43685 1 Okfn 1 Ckan 2023-08-08 N/A 8.8 HIGH
CKAN through 2.9.6 account takeovers by unauthenticated users when an existing user id is sent via an HTTP POST request. This allows a user to take over an existing account including superuser accounts.