Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-qp8h-c7qp-m297

Опубликовано: 15 сент. 2026
Источник: github
Github: Не прошло ревью
CVSS4: 8.4
CVSS3: 8.5

Описание

pgweb through 0.17.0 leaves the POST /api/connect endpoint unguarded when connect-backend authorization is configured, allowing attackers to supply arbitrary database connection strings. Attackers can bypass the resource-to-database mapping by providing a custom session identifier and connection URL to access unauthorized databases and internal services.

pgweb through 0.17.0 leaves the POST /api/connect endpoint unguarded when connect-backend authorization is configured, allowing attackers to supply arbitrary database connection strings. Attackers can bypass the resource-to-database mapping by providing a custom session identifier and connection URL to access unauthorized databases and internal services.

EPSS

Процентиль: 17%
0.00253
Низкий

8.4 High

CVSS4

8.5 High

CVSS3

Дефекты

CWE-862

Связанные уязвимости

CVSS3: 8.5
nvd
4 дня назад

pgweb through 0.17.0 leaves the POST /api/connect endpoint unguarded when connect-backend authorization is configured, allowing attackers to supply arbitrary database connection strings. Attackers can bypass the resource-to-database mapping by providing a custom session identifier and connection URL to access unauthorized databases and internal services.

EPSS

Процентиль: 17%
0.00253
Низкий

8.4 High

CVSS4

8.5 High

CVSS3

Дефекты

CWE-862