{"id":"CVE-2022-43685","aliases":["GHSA-m2xp-jxfg-qq6g","PYSEC-2022-42987"],"url":"https://o3.security/vulnerability/CVE-2022-43685","summary":"CKAN contains Improper Authentication leading to account takeover","details":"CKAN through 2.9.6 account takeovers by unauthenticated users when an existing user id is sent via an HTTP POST request. This allows a user to take over an existing account including superuser accounts.","published":"2022-11-22T00:00:00Z","modified":"2026-08-12T03:51:18.185570464Z","cvss":{"score":8.8,"severity":"HIGH","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"},"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"PyPI","name":"ckan","fixedVersion":"2.9.7"}],"fix":null,"references":[{"type":"WEB","url":"https://ckan.org/"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2022/43xxx/CVE-2022-43685.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2022-43685"},{"type":"ARTICLE","url":"https://ckan.org/blog/get-latest-patch-releases-your-ckan-site-october-2022"},{"type":"WEB","url":"https://ckan.org"},{"type":"PACKAGE","url":"https://github.com/ckan/ckan"},{"type":"WEB","url":"https://github.com/pypa/advisory-database/tree/main/vulns/ckan/PYSEC-2022-42987.yaml"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-12T03:51:18.185570464Z"}}