CKAN
cpe:2.3:a:okfn:ckan:*:*:*:*:*:*:*
- <= 2.11.4
A vulnerability in CKAN, an open-source data management system, allows for SMTP server spoofing with any certificate, including self-signed ones. This issue, present in CKAN versions through 2.11.4, leaves credentials and all sent emails vulnerable to man-in-the-middle attacks.
Exploitation of this vulnerability could lead to interception of credentials and emails sent via the configured SMTP server.
Users can upgrade to CKAN version 2.10.10 or 2.11.5 to address this vulnerability.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.