Session Fixation Vulnerability in pgAdmin Affecting LDAP Authentication
CVE-2023-1907

7.5HIGH

Key Information:

Vendor

Pgadmin

Status
Vendor
CVE Published:
9 January 2025

What is CVE-2023-1907?

A vulnerability in pgAdmin's server mode has been identified, where users may inadvertently attach to another user's session while logging in via LDAP authentication. This occurs if multiple connection attempts happen at the same time, potentially allowing an unauthorized party to gain access to an active session. It is essential to implement security measures to prevent such session-related issues and to ensure that your pgAdmin configurations are secure.

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2023-1907 : Session Fixation Vulnerability in pgAdmin Affecting LDAP Authentication