CVE-2023-1907

HIGH

pgadmin < 7.0 - Unauthenticated Session Hijacking via LDAP Authentication

Title source: llm
STIX 2.1

Description

A vulnerability was found in pgadmin. Users logging into pgAdmin running in server mode using LDAP authentication may be attached to another user's session if multiple connection attempts occur simultaneously.

References (2)

Core 2
Core References
Third Party Advisory vdb-entry x_refsource_redhat
https://access.redhat.com/security/cve/CVE-2023-1907
Issue Tracking, Third Party Advisory issue-tracking x_refsource_redhat
https://bugzilla.redhat.com/show_bug.cgi?id=2218384

Scores

CVSS v3 8.0
EPSS 0.0010
EPSS Percentile 27.4%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:C/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-276 CWE-488
Status published
Products (2)
pgadmin/pgadmin < 7.0
pypi/pgadmin4 0 - 7.0PyPI
Published Jan 09, 2025
Tracked Since Feb 18, 2026