Advisory Database
  • Advisories
  • Dependency Scanning
  1. pypi
  2. ›
  3. ckan
  4. ›
  5. CVE-2023-22746

CVE-2023-22746: Use of Insufficiently Random Values

February 3, 2023 (updated November 7, 2023)

CKAN is an open-source DMS (data management system) for powering data hubs and data portals. When creating a new container based on one of the Docker images listed below, the same secret key was being used by default. If the users didn’t set a custom value via environment variables in the .env file, that key was shared across different CKAN instances, making it easy to forge authentication requests. Users overriding the default secret key in their own .env file are not affected by this issue. Note that the legacy images (ckan/ckan) located in the main CKAN repo are not affected by this issue. The affected images are ckan/ckan-docker, (ckan/ckan-base images), okfn/docker-ckan (openknowledge/ckan-base and openknowledge/ckan-dev images) keitaroinc/docker-ckan (keitaro/ckan images).

References

  • github.com/ckan/ckan/commit/44af0f0a148fcc0e0fbcf02fe69b7db13459a84b
  • github.com/ckan/ckan/commit/4c22c135fa486afa13855d1cdb9765eaf418d2aa
  • github.com/ckan/ckan/security/advisories/GHSA-pr8j-v4c8-h62x
  • nvd.nist.gov/vuln/detail/CVE-2023-22746

Code Behaviors & Features

Detect and mitigate CVE-2023-22746 with GitLab Dependency Scanning

Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →

Affected versions

All versions before 2.8.12, all versions starting from 2.9.0 before 2.9.7

Fixed versions

  • 2.8.12
  • 2.9.7

Solution

Upgrade to versions 2.8.12, 2.9.7 or above.

Impact 7.5 HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Learn more about CVSS

Weakness

  • CWE-330: Use of Insufficiently Random Values

Source file

pypi/ckan/CVE-2023-22746.yml

Spotted a mistake? Edit the file on GitLab.

  • Site Repo
  • About GitLab
  • Terms
  • Privacy Statement
  • Contact

Page generated Wed, 14 May 2025 12:15:44 +0000.