CKAN contains Improper Authentication leading to account takeover
        
  High severity
        
          GitHub Reviewed
      
        Published
          Nov 22, 2022 
          to the GitHub Advisory Database
          •
          Updated Apr 29, 2025 
      
  
Description
        Published by the National Vulnerability Database
      Nov 22, 2022 
    
  
        Published to the GitHub Advisory Database
      Nov 22, 2022 
    
  
        Reviewed
      Feb 2, 2023 
    
  
        Last updated
      Apr 29, 2025 
    
  
CKAN through 2.9.6 account takeovers by unauthenticated users when an existing user id is sent via an HTTP POST request. This allows a user to take over an existing account including superuser accounts.
References