Skip to content

Excessive permissions on ckan user

High
amercader published GHSA-c74x-xfvr-x5wg May 24, 2023

Package

docker ckan-base (Docker)

Affected versions

<2.9.9, <2.10.1

Patched versions

2.9.9, 2.10.1
docker ckan-dev (Docker)
<2.9.9, <2.10.1
2.9.9, 2.10.1

Description

Bugs

  1. The ckan user (equivalent to www-data) owned code and configuration files in the docker container.
  2. The ckan user had the permissions to use sudo

Impact

These bugs allow for (1) code execution or (2) privilege escalation if an arbitrary file write bug is available.

Patches

These vulnerabilities have been fixed in the images tagged ckan-base:2.9.9, ckan-base:2.9.9-dev, ckan-base:2.10.1 and ckan-base:2.10.1-dev

Severity

High

CVE ID

CVE-2023-32696

Weaknesses

No CWEs