Local Execution Vulnerability in pgAgent by pgAdmin
CVE-2025-0218

7.1HIGH

Key Information:

Vendor

pgAdmin

Status
Vendor
CVE Published:
7 January 2025

What is CVE-2025-0218?

In pgAgent versions before 4.2.3, a flaw occurs when batch jobs are executed, involving the creation and execution of scripts in a temporary directory. The vulnerability arises due to an insufficiently seeded random number generator utilized for generating directory names. This can allow a local attacker to pre-create the temporary directory, subsequently blocking pgAgent from completing job executions, thereby disrupting the functionality of scheduled tasks across the system.

References

CVSS V3.1

Score:
7.1
Severity:
HIGH
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

.