Количество 5
Количество 5
CVE-2026-7820
Improper restriction of excessive authentication attempts (CWE-307) in pgAdmin 4. pgAdmin enforces MAX_LOGIN_ATTEMPTS only inside its custom /authenticate/login view. Flask-Security's default /login view, which is registered automatically by security.init_app() and is reachable on every server, never consulted the User.locked field: pgAdmin's User model relied on Flask-Security's UserMixin.is_locked() (which always returns 'not locked') and Flask-Login's is_active (which only checks the active column, not locked). An attacker who triggered an account lockout via /authenticate/login could therefore obtain a session by re-submitting valid credentials directly to /login, defeating the brute-force-protection control for accounts using the INTERNAL authentication source. The same bypass also means that login attempts via /login are never rate-limited, so an attacker can perform an unbounded online password-guessing attack against INTERNAL accounts regardless of MAX_LOGIN_ATTEMPTS. Fix ove
CVE-2026-7820
Improper restriction of excessive authentication attempts (CWE-307) in ...
GHSA-hv9p-2pqf-r5w3
pgAdmin 4: Improper restriction of excessive authentication attempts
BDU:2026-09127
Уязвимость механизма блокировки паролей (MAX_LOGIN_ATTEMPTS) инструмента управления базами данных pgAdmin 4, позволяющая нарушителю получить несанкционированный доступ к защищаемой информации
ROS-20260729-73-0031
Уязвимость pgadmin4
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2026-7820 Improper restriction of excessive authentication attempts (CWE-307) in pgAdmin 4. pgAdmin enforces MAX_LOGIN_ATTEMPTS only inside its custom /authenticate/login view. Flask-Security's default /login view, which is registered automatically by security.init_app() and is reachable on every server, never consulted the User.locked field: pgAdmin's User model relied on Flask-Security's UserMixin.is_locked() (which always returns 'not locked') and Flask-Login's is_active (which only checks the active column, not locked). An attacker who triggered an account lockout via /authenticate/login could therefore obtain a session by re-submitting valid credentials directly to /login, defeating the brute-force-protection control for accounts using the INTERNAL authentication source. The same bypass also means that login attempts via /login are never rate-limited, so an attacker can perform an unbounded online password-guessing attack against INTERNAL accounts regardless of MAX_LOGIN_ATTEMPTS. Fix ove | CVSS3: 6.5 | 0% Низкий | 3 месяца назад | |
CVE-2026-7820 Improper restriction of excessive authentication attempts (CWE-307) in ... | CVSS3: 6.5 | 0% Низкий | 3 месяца назад | |
GHSA-hv9p-2pqf-r5w3 pgAdmin 4: Improper restriction of excessive authentication attempts | CVSS3: 6.5 | 0% Низкий | 3 месяца назад | |
BDU:2026-09127 Уязвимость механизма блокировки паролей (MAX_LOGIN_ATTEMPTS) инструмента управления базами данных pgAdmin 4, позволяющая нарушителю получить несанкционированный доступ к защищаемой информации | CVSS3: 6.5 | 0% Низкий | 3 месяца назад | |
ROS-20260729-73-0031 Уязвимость pgadmin4 | CVSS3: 6.5 | 0% Низкий | 6 дней назад |
Уязвимостей на страницу