Session Fixation Vulnerability in pgAdmin Affecting LDAP Authentication
CVE-2023-1907
8HIGH
Key Information:
- Status
- Vendor
- CVE Published:
- 9 January 2025
Summary
A vulnerability in pgAdmin's server mode has been identified, where users may inadvertently attach to another user's session while logging in via LDAP authentication. This occurs if multiple connection attempts happen at the same time, potentially allowing an unauthorized party to gain access to an active session. It is essential to implement security measures to prevent such session-related issues and to ensure that your pgAdmin configurations are secure.
References
CVSS V3.1
Score:
8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved