id: PYSEC-2021-841 details: "In CKAN, versions 2.9.0 to 2.9.3 are affected by a stored XSS vulnerability\ \ via SVG file upload of users\u2019 profile picture. This allows low privileged\ \ application users to store malicious scripts in their profile picture. These scripts\ \ are executed in a victim\u2019s browser when they open the malicious profile picture" affected: - package: name: ckan ecosystem: PyPI purl: pkg:pypi/ckan ranges: - type: ECOSYSTEM events: - introduced: 2.9.0 - fixed: 2.9.4 versions: - 2.9.0 - 2.9.1 - 2.9.2 - 2.9.3 references: - type: WEB url: https://www.whitesourcesoftware.com/vulnerability-database/CVE-2021-25967 - type: ADVISORY url: https://github.com/advisories/GHSA-6w9p-88qg-p3g3 aliases: - CVE-2021-25967 - GHSA-6w9p-88qg-p3g3 modified: '2021-12-13T06:35:10.687046Z' published: '2021-12-01T14:15:00Z'