Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-cr8c-972v-rmp3

Опубликовано: 17 мар. 2022
Источник: github
Github: Прошло ревью
CVSS3: 6.5

Описание

pgAdmin 4 Path Traversal vulnerability

When run in server mode, pgAdmin 4 allows users to store files on the server under individual storage directories. Files such as SQL scripts may be uploaded through the user interface. The URI to which upload requests are made fails to validate the upload path to prevent path traversal techniques being used to store files outside of the storage directory. A malicious, but authorised and authenticated user can construct an HTTP request using their existing CSRF token and session cookie to manually upload files to any location that the operating system user account under which pgAdmin is running has permission to write.

Пакеты

Наименование

pgadmin4

pip
Затронутые версииВерсия исправления

< 6.7

6.7

EPSS

Процентиль: 59%
0.00386
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-22
CWE-434

Связанные уязвимости

CVSS3: 6.5
nvd
почти 4 года назад

A malicious, but authorised and authenticated user can construct an HTTP request using their existing CSRF token and session cookie to manually upload files to any location that the operating system user account under which pgAdmin is running has permission to write.

CVSS3: 6.5
debian
почти 4 года назад

A malicious, but authorised and authenticated user can construct an HT ...

suse-cvrf
почти 4 года назад

Security update for pgadmin4

EPSS

Процентиль: 59%
0.00386
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-22
CWE-434