CVE-2022-4223: Code Injection
The pgAdmin server includes an HTTP API that is intended to be used to validate the path a user selects to external PostgreSQL utilities such as pgdump and pgrestore. The utility is executed by the server to determine what PostgreSQL version it is from. Versions of pgAdmin prior to 6.17 failed to properly secure this API, which could allow an unauthenticated user to call it with a path of their choosing, such as a UNC path to a server they control on a Windows machine. This would cause an appropriately named executable in the target path to be executed by the pgAdmin server.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID of this issue?
The vulnerability ID is CVE-2022-4223.
What is the title of this vulnerability?
The title of this vulnerability is 'The pgAdmin server includes an HTTP API that is intended to be used to validate the path a user sele…'
What is the severity of CVE-2022-4223?
The severity of CVE-2022-4223 is high with a severity value of 8.8.
What software is affected by CVE-2022-4223?
The affected software is Postgresql Pgadmin (up to version 6.17) and Fedoraproject Fedora (version 37).
How can I fix CVE-2022-4223?
To fix CVE-2022-4223, you should update pgAdmin to version 6.17 or higher.