Bugzilla – Bug 1207238
VUL-0: CVE-2023-22298: pgadmin4: Open URL Redirect Vulnerability
Last modified: 2023-04-04 03:26:18 UTC
rh#2161637 Open redirect vulnerability in pgAdmin 4 versions prior to v6.14 allows a remote unauthenticated attacker to redirect a user to an arbitrary web site and conduct a phishing attack by having a user to access a specially crafted URL. Upstream fix: https://github.com/pgadmin-org/pgadmin4/commit/e2b00dda1b15a1793f365544fce2c46e47b7a47e https://github.com/pgadmin-org/pgadmin4 https://github.com/pgadmin-org/pgadmin4/issues/5343 https://jvn.jp/en/jp/JVN03832974/index.html https://www.pgadmin.org/ References: https://bugzilla.redhat.com/show_bug.cgi?id=2161637 http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2023-22298 https://github.com/pgadmin-org/pgadmin4 https://github.com/pgadmin-org/pgadmin4/issues/5343 https://www.cve.org/CVERecord?id=CVE-2023-22298 https://www.pgadmin.org/ https://jvn.jp/en/jp/JVN03832974/index.html
Affected: - SUSE:SLE-15-SP3:Update - openSUSE:Factory
This should be fixed with https://build.suse.de/request/show/291437
SUSE-SU-2023:1739-1: An update that solves one vulnerability can now be installed. Category: security (moderate) Bug References: 1207238 CVE References: CVE-2023-22298 Sources used: openSUSE Leap 15.4 (src): pgadmin4-4.30-150300.3.6.1 Server Applications Module 15-SP4 (src): pgadmin4-4.30-150300.3.6.1 SUSE Linux Enterprise Real Time 15 SP3 (src): pgadmin4-4.30-150300.3.6.1 NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination.