SB2025041813 - Privilege escalation in pgAdmin
Published: April 18, 2025
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Resource management error (CVE-ID: CVE-2023-1907)
The vulnerability allows a remote attacker to escalate privileges within the application.
The vulnerability exists due to improper management of internal resources within the application. Users logging into pgAdmin running in server mode using LDAP
authentication may be attached to another user's session if multiple
connection attempts occur simultaneously.
Remediation
Install update from vendor's website.