Session Fixation Affecting ckan package, versions [2.10.0,2.10.9)[2.11.0,2.11.4)


Severity

Recommended
0.0
high
0
10

CVSS assessment by Snyk's Security Team. Learn more

Threat Intelligence

EPSS
0.03% (9th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-PYTHON-CKAN-13774796
  • published30 Oct 2025
  • disclosed29 Oct 2025
  • creditUnknown

Introduced: 29 Oct 2025

NewCVE-2025-64100  (opens in a new tab)
CWE-384  (opens in a new tab)

How to fix?

Upgrade ckan to version 2.10.9, 2.11.4 or higher.

Overview

ckan is a world’s leading Open Source data portal platform.

It powers dozens of Open Data portals around the world, including data.gov, open.canada.ca and europeandataportal.eu but also regional, research and community organizations.

It makes easy to publish, share and find data online and is fully customizable via extensions and plugins.

Affected versions of this package are vulnerable to Session Fixation via the login() function in the views/user.py file. An attacker can hijack user sessions by setting a crafted session cookie on the victim's browser or by stealing a valid session identifier.

Note: This is only exploitable if server-side session storage is configured instead of the default cookie-based session storage.

CVSS Base Scores

version 4.0
version 3.1