CVE-2023-22298: Medium severity pgadmin 4 vulnerability
Published Jan 17, 2023
·Updated
Open redirect vulnerability in pgAdmin 4 versions prior to v6.14 allows a remote unauthenticated attacker to redirect a user to an arbitrary web site and conduct a phishing attack by having a user to access a specially crafted URL.
Affected Software
4 affected componentsFixes available
pip/pgadmin4<6.14
6.14
pgAdmin Pgadmin 4 Postgresql>=4.0<6.14
Fedoraproject Fedora=36
pgAdmin Pgadmin Postgresql>=4.0<6.14
Remediation
Patch Available
Event History
Jan 17, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
DescriptionWeakness
Data Sourced
via NVD·10:15 AM
RemedyDescriptionSeverityWeaknessAffected Software
Advisory Published
via GitHub·12:30 PM
Frequently Asked Questions
1
What is the vulnerability ID for this vulnerability?
The vulnerability ID for this vulnerability is CVE-2023-22298.
2
What is the severity of CVE-2023-22298?
The severity of CVE-2023-22298 is medium with a CVSS score of 6.1.
3
Which software versions are affected by CVE-2023-22298?
pgAdmin 4 versions prior to v6.14 and Fedora 36 are affected by CVE-2023-22298.
4
How does the vulnerability in pgAdmin 4 versions prior to v6.14 work?
The vulnerability allows a remote unauthenticated attacker to redirect a user to an arbitrary website and conduct a phishing attack by having the user access a specially crafted URL.
5
How can I fix the Open redirect vulnerability in pgAdmin 4 versions prior to v6.14?
Upgrade to pgAdmin 4 version 6.14 or later to fix the vulnerability.