id: PYSEC-2026-1248 published: "2026-07-07T14:34:39.100125Z" modified: "2026-07-07T17:23:54.702740Z" aliases: - CVE-2024-41674 - GHSA-2rqw-cfhc-35fh summary: CKAN may leak Solr credentials via error message in package_search action details: "If there were connection issues with the Solr server, the internal Solr URL (potentially including credentials) could be leaked to `package_search` calls as part of the returned error message\n\n### Patches\nThis has been patched in CKAN 2.10.5 and 2.11.0\n" affected: - package: name: ckan ecosystem: PyPI purl: pkg:pypi/ckan ranges: - type: ECOSYSTEM events: - introduced: 2.0.0 - fixed: 2.10.5 versions: - "2.0" - 2.0.1 - 2.0.7 - 2.0.8 - "2.1" - 2.1.1 - 2.1.5 - 2.1.6 - 2.10.0 - 2.10.1 - 2.10.3 - 2.10.4 - "2.2" - 2.2.1 - 2.2.3 - 2.2.4 - "2.3" - 2.3.1 - 2.3.2 - 2.3.3 - 2.3.4 - 2.3.5 - 2.4.0 - 2.4.1 - 2.4.2 - 2.4.3 - 2.4.4 - 2.4.5 - 2.4.8 - 2.4.9 - 2.5.0 - 2.5.1 - 2.5.2 - 2.5.3 - 2.5.4 - 2.5.6 - 2.5.7 - 2.5.8 - 2.5.9 - 2.6.0 - 2.6.1 - 2.6.3 - 2.6.4 - 2.6.5 - 2.6.6 - 2.6.7 - 2.6.8 - 2.6.9 - 2.7.0 - 2.7.1 - 2.7.10 - 2.7.11 - 2.7.12 - 2.7.2 - 2.7.3 - 2.7.4 - 2.7.5 - 2.7.6 - 2.7.7 - 2.7.8 - 2.7.9 - 2.8.0 - 2.8.1 - 2.8.10 - 2.8.11 - 2.8.12 - 2.8.2 - 2.8.3 - 2.8.4 - 2.8.5 - 2.8.6 - 2.8.7 - 2.8.8 - 2.8.9 - 2.9.0 - 2.9.1 - 2.9.10 - 2.9.11 - 2.9.2 - 2.9.3 - 2.9.4 - 2.9.5 - 2.9.6 - 2.9.7 - 2.9.8 - 2.9.9 references: - type: WEB url: https://github.com/ckan/ckan/security/advisories/GHSA-2rqw-cfhc-35fh - type: ADVISORY url: https://nvd.nist.gov/vuln/detail/CVE-2024-41674 - type: WEB url: https://github.com/ckan/ckan/commit/f6b032cd7082d784938165bbd113557639002ca7 - type: PACKAGE url: https://github.com/ckan/ckan - type: PACKAGE url: https://pypi.org/project/ckan - type: ADVISORY url: https://github.com/advisories/GHSA-2rqw-cfhc-35fh severity: - type: CVSS_V3 score: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N - type: CVSS_V4 score: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N