CKAN through 2.9.6 account takeovers by unauthenticated users when an existing user id is sent via an HTTP POST request. This allows a user to take over an existing account including superuser accounts.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Ckan | Okfn | * | 2.8.12 (excluding) |
Ckan | Okfn | 2.9.0 (including) | 2.9.7 (excluding) |