Back

HIGH

pgadmin4: Unauthenticated remote code execution while validating the binary path

Published Dec 13, 2022

Description

The pgAdmin server includes an HTTP API that is intended to be used to validate the path a user selects to external PostgreSQL utilities such as pg_dump and pg_restore. The utility is executed by the server to determine what PostgreSQL version it is from. Versions of pgAdmin prior to 6.17 failed to properly secure this API, which could allow an unauthenticated user to call it with a path of their choosing, such as a UNC path to a server they control on a Windows machine. This would cause an appropriately named executable in the target path to be executed by the pgAdmin server.

Affected products

Remediation

Red Hat statement

This issue does not affect users running pgAdmin in desktop mode.

References (9)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner redhat
Published Dec 13, 2022
Updated Apr 14, 2025
Reserved Nov 30, 2022
CISA Vulnrichment
Updated Apr 14, 2025
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Important
Public date Dec 2, 2022
ENISA EUVD
Assigner redhat
Published Dec 13, 2022
Updated Apr 14, 2025
Exploited since n/a
EUVD-2022-7489 GHSA-3V6V-2X6P-32MC