CVE-2023-0241: Path Traversal
Published Mar 27, 2023
·Updated
pgAdmin 4 versions prior to v6.19 contains a directory traversal vulnerability. A user of the product may change another user's settings or alter the database.
Affected Software
3 affected componentsFixes available
PostgreSQL pgAdmin 4<6.19
pgAdmin pgAdmin 4<6.19
pip/pgadmin4<=6.18
6.19
Remediation
Patch Available
Event History
Mar 27, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
DescriptionWeakness
Advisory Published
via GitHub·09:30 PM
Data Sourced
via GitHub·09:30 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the vulnerability in pgAdmin 4 versions prior to v6.19?
The vulnerability is a directory traversal vulnerability.
2
What can an attacker do with the directory traversal vulnerability in pgAdmin 4 versions prior to v6.19?
An attacker can change another user's settings or alter the database.
3
What is the severity of CVE-2023-0241?
The severity of CVE-2023-0241 is medium with a CVSS score of 6.5.
4
How do I fix the directory traversal vulnerability in pgAdmin 4 versions prior to v6.19?
Update to pgAdmin 4 version 6.19 or above to fix the vulnerability.
5
Where can I find more information about CVE-2023-0241?
You can find more information about CVE-2023-0241 at the following links: [GitHub](https://github.com/pgadmin-org/pgadmin4/issues/5734) and [JVN](https://jvn.jp/en/jp/JVN01398015/).