CVE-2022-0959
pgAdmin 4 Path Traversal vulnerability
6.5
MEDIUM
CVSS 3.1
EPSS 0.93%
描述
When run in server mode, pgAdmin 4 allows users to store files on the server under individual storage directories. Files such as SQL scripts may be uploaded through the user interface. The URI to which upload requests are made fails to validate the upload path to prevent path traversal techniques being used to store files outside of the storage directory. A malicious, but authorised and authenticated user can construct an HTTP request using their existing CSRF token and session cookie to manually upload files to any location that the operating system user account under which pgAdmin is running has permission to write.
如何修補 CVE-2022-0959
要修補 CVE-2022-0959,請將受影響套件升級到下列已修補版本。
- —升級至 6.7 或更新版本
- —升級至 6.7 或更新版本
CVE-2022-0959 正在被利用嗎?
低 — EPSS 為 0.9%,目前沒有觀察到大規模利用活動。
受影響套件(2)
- from 0, < 6.7
- from 0, < 6.7
CVSS 分數
| 來源 | 版本 | 嚴重程度 | 向量 |
|---|---|---|---|
| osv | CVSS 3.1 | MEDIUM6.5 | CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N |