ckan

condav2.9.4

CKAN Software for making open data websites.

License GNU Affero General Public v3 or later (AGPLv3+)2 versions1 maintainers0 deps44 weekly dl
ckan/ckan
19
/ 100
Health
do not use

ckan has critical vulnerabilities — do not use

Update to >= 2.9.7 to fix known vulnerabilities

  • Low health score (19/100)
  • 2 high severity vulnerabilities
  • 1 critical vulnerabilities
Health breakdown0 – 100
5/25
maintenance
0/20
popularity
0/25
security
12/15
maturity
2/15
community
Vulnerabilities
11
1 critical2 high7 medium1 low
Advisories (11)
SeverityIDSummaryFixed in
mediumCVE-2025-54384CKAN vulnerable to stored XSS in resource description2.10.9
mediumCVE-2024-41674CKAN may leak Solr credentials via error message in package_search action2.10.5
criticalCVE-2023-32321Ckan remote code execution and private information access via crafted resource ids2.9.9
mediumCVE-2021-25967Cross-site Scripting in CKAN2.10.0
mediumCVE-2023-50248Out of memory error when submitting the dataset form with a specially-crafted field2.10.3
highCVE-2025-24372CKAN has an XSS vector in user uploaded images in group/org and user profiles2.11.2
mediumCVE-2024-27097Potential log injection in reset user endpoint in CKAN2.10.4
mediumCVE-2024-43371Potential access to sensitive URLs via CKAN extensions (SSRF)2.10.5
highCVE-2022-43685CKAN contains Improper Authentication leading to account takeover2.9.7
mediumCVE-2024-41675CKAN has Cross-site Scripting vector in the Datatables view plugin2.10.5
unknownCVE-2022-43685CKAN through 2.9.6 account takeovers by unauthenticated users when an existing user id is sent via an HTTP POST request. This allows a user to take over an existing account including superuser accounts.2.9.7

Health History

Dependency Tree

License Audit

API access

Get this data programmatically — free, no authentication.

curl https://depscope.dev/api/check/conda/ckan

First published · 2019-10-23 05:03:24.450000+00:00

Last updated · 2025-04-22 14:57:15.296000+00:00

ckan — Health Score 19/100 | DepScope