Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 5

Количество 5

nvd логотип

CVE-2026-7820

3 месяца назад

Improper restriction of excessive authentication attempts (CWE-307) in pgAdmin 4. pgAdmin enforces MAX_LOGIN_ATTEMPTS only inside its custom /authenticate/login view. Flask-Security's default /login view, which is registered automatically by security.init_app() and is reachable on every server, never consulted the User.locked field: pgAdmin's User model relied on Flask-Security's UserMixin.is_locked() (which always returns 'not locked') and Flask-Login's is_active (which only checks the active column, not locked). An attacker who triggered an account lockout via /authenticate/login could therefore obtain a session by re-submitting valid credentials directly to /login, defeating the brute-force-protection control for accounts using the INTERNAL authentication source. The same bypass also means that login attempts via /login are never rate-limited, so an attacker can perform an unbounded online password-guessing attack against INTERNAL accounts regardless of MAX_LOGIN_ATTEMPTS. Fix ove

CVSS3: 6.5
EPSS: Низкий
debian логотип

CVE-2026-7820

3 месяца назад

Improper restriction of excessive authentication attempts (CWE-307) in ...

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-hv9p-2pqf-r5w3

3 месяца назад

pgAdmin 4: Improper restriction of excessive authentication attempts

CVSS3: 6.5
EPSS: Низкий
fstec логотип

BDU:2026-09127

3 месяца назад

Уязвимость механизма блокировки паролей (MAX_LOGIN_ATTEMPTS) инструмента управления базами данных pgAdmin 4, позволяющая нарушителю получить несанкционированный доступ к защищаемой информации

CVSS3: 6.5
EPSS: Низкий
redos логотип

ROS-20260729-73-0031

6 дней назад

Уязвимость pgadmin4

CVSS3: 6.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2026-7820

Improper restriction of excessive authentication attempts (CWE-307) in pgAdmin 4. pgAdmin enforces MAX_LOGIN_ATTEMPTS only inside its custom /authenticate/login view. Flask-Security's default /login view, which is registered automatically by security.init_app() and is reachable on every server, never consulted the User.locked field: pgAdmin's User model relied on Flask-Security's UserMixin.is_locked() (which always returns 'not locked') and Flask-Login's is_active (which only checks the active column, not locked). An attacker who triggered an account lockout via /authenticate/login could therefore obtain a session by re-submitting valid credentials directly to /login, defeating the brute-force-protection control for accounts using the INTERNAL authentication source. The same bypass also means that login attempts via /login are never rate-limited, so an attacker can perform an unbounded online password-guessing attack against INTERNAL accounts regardless of MAX_LOGIN_ATTEMPTS. Fix ove

CVSS3: 6.5
0%
Низкий
3 месяца назад
debian логотип
CVE-2026-7820

Improper restriction of excessive authentication attempts (CWE-307) in ...

CVSS3: 6.5
0%
Низкий
3 месяца назад
github логотип
GHSA-hv9p-2pqf-r5w3

pgAdmin 4: Improper restriction of excessive authentication attempts

CVSS3: 6.5
0%
Низкий
3 месяца назад
fstec логотип
BDU:2026-09127

Уязвимость механизма блокировки паролей (MAX_LOGIN_ATTEMPTS) инструмента управления базами данных pgAdmin 4, позволяющая нарушителю получить несанкционированный доступ к защищаемой информации

CVSS3: 6.5
0%
Низкий
3 месяца назад
redos логотип
ROS-20260729-73-0031

Уязвимость pgadmin4

CVSS3: 6.5
0%
Низкий
6 дней назад

Уязвимостей на страницу