CVE-2023-22626

HIGH

PgHero < 3.1.0 - Information Disclosure via EXPLAIN Error Message

Title source: llm
STIX 2.1

Description

PgHero before 3.1.0 allows Information Disclosure via EXPLAIN because query results may be present in an error message. (Depending on database user privileges, this may only be information from the database, or may be information from file contents on the database server.)

References (1)

Core 1
Core References
Exploit, Third Party Advisory
https://github.com/ankane/pghero/issues/439

Scores

CVSS v3 7.5
EPSS 0.0011
EPSS Percentile 29.7%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-209
Status published
Products (2)
pghero_project/pghero 0.1.1 - 3.1.0
rubygems/pghero 0 - 3.1.0RubyGems
Published Jan 05, 2023
Tracked Since Feb 18, 2026