A vulnerability was found in pgadmin. Users logging into pgAdmin running in server mode using LDAP authentication may be attached to another user's session if multiple connection attempts occur simultaneously.
Metrics
Affected Vendors & Products
References
History
Fri, 20 Jun 2025 18:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Pgadmin
Pgadmin pgadmin |
|
CPEs | cpe:2.3:a:pgadmin:pgadmin:*:*:*:*:*:postgresql:*:* | |
Vendors & Products |
Pgadmin
Pgadmin pgadmin |
Thu, 06 Feb 2025 15:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Weaknesses | CWE-488 |
Thu, 06 Feb 2025 08:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
References |
|
Thu, 09 Jan 2025 15:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Weaknesses | CWE-276 | |
Metrics |
ssvc
|
Thu, 09 Jan 2025 07:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | A vulnerability was found in pgadmin. Users logging into pgAdmin running in server mode using LDAP authentication may be attached to another user's session if multiple connection attempts occur simultaneously. | |
Title | Pgadmin: users authenticated simultaneously via ldap may be attached to the wrong session | |
References |
| |
Metrics |
cvssV3_1
|

Status: PUBLISHED
Assigner: redhat
Published: 2025-01-09T07:26:48.686Z
Updated: 2025-02-06T16:30:15.701Z
Reserved: 2023-04-06T10:56:57.129Z
Link: CVE-2023-1907

Updated: 2025-01-09T14:52:59.667Z

Status : Analyzed
Published: 2025-01-09T08:15:24.477
Modified: 2025-06-20T17:57:08.107
Link: CVE-2023-1907

No data.