Lucene search

K
githubGitHub Advisory DatabaseGHSA-VF99-XW26-86G5
HistoryJan 05, 2023 - 9:30 a.m.

PgHero Allows Information Disclosure Through EXPLAIN Feature

2023-01-0509:30:28
CWE-209
GitHub Advisory Database
github.com
15
pghero
information disclosure
explain
query results
error message
database user privileges
file contents

CVSS3

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

EPSS

0.002

Percentile

58.8%

PgHero before 3.1.0 allows Information Disclosure via EXPLAIN because query results may be present in an error message. (Depending on database user privileges, this may only be information from the database, or may be information from file contents on the database server.)

Affected configurations

Vulners
Node
pghero_projectpgheroRange<3.1.0ruby
VendorProductVersionCPE
pghero_projectpghero*cpe:2.3:a:pghero_project:pghero:*:*:*:*:*:ruby:*:*

CVSS3

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

EPSS

0.002

Percentile

58.8%

Related for GHSA-VF99-XW26-86G5