Open redirect in pgAdmin - CVE-2023-22298

 

Open redirect in pgAdmin - CVE-2023-22298

Published: January 17, 2023


Vulnerability identifier: #VU71214
CSH Severity: Low
CVSS v4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2023-22298
CWE-ID: CWE-601
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to redirect victims to arbitrary URL.

The vulnerability exists due to improper sanitization of user-supplied data. A remote attacker can create a link that leads to a trusted website, however, when clicked, redirects the victim to arbitrary domain.


Affected software

pgAdmin
SUSE Linux Enterprise Real Time 15
SUSE Linux Enterprise High Performance Computing 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Manager Proxy
SUSE Manager Retail Branch Server
SUSE Manager Server
Server Applications Module
openSUSE Leap
Fedora
pgadmin4
pgadmin4-debuginfo
pgadmin4-doc
pgadmin4-web-uwsgi
pgadmin4-web

How to mitigate CVE-2023-22298

Install updates from vendor's website.

pgAdmin - update to 6.14
pgadmin4 - update to 4.30-150300.3.6.1
pgadmin4-debuginfo - update to 4.30-150300.3.6.1
pgadmin4-doc - update to 4.30-150300.3.6.1
pgadmin4-web-uwsgi - update to 4.30-150300.3.6.1
pgadmin4-web - update to 4.30-150300.3.6.1
pgadmin4 - addressed in versions 6.12-7.fc36, 6.19-1.fc36

External References

Related Security Bulletins