A vulnerability was found in pgadmin. Users logging into pgAdmin running in server mode using LDAP authentication may be attached to another user's session if multiple connection attempts occur simultaneously.
The product does not sufficiently enforce boundaries between the states of different sessions, causing data to be provided to, or used by, the wrong session.
During installation, installed file permissions are set to allow anyone to modify those files.
Link | Tags |
---|---|
https://access.redhat.com/security/cve/CVE-2023-1907 | vdb entry |
https://bugzilla.redhat.com/show_bug.cgi?id=2218384 | issue tracking |