CVE-2022-43685
CKAN through 2.9.6 account takeovers by unauthenticated users when an existing user id is sent via an HTTP POST request.
CKAN through 2.9.6 account takeovers by unauthenticated users when an existing user id is sent via an HTTP POST request. This allows a user to take over an existing account including superuser accounts.
HIGH · CVSS 8.8
EPSS 0.00864
Schedule remediation
- CVSS base score ≥ 7.0
Sigma rules0
YARA rules0