Back to bug 2063759

Who When What Removed Added
Sandipan Roy 2022-03-14 10:51:11 UTC CC astra, devrim, extras-orphan, stuart
Sandipan Roy 2022-03-14 10:52:17 UTC Fixed In Version pgadmin 6.7
Sandipan Roy 2022-03-14 10:53:30 UTC Depends On 2063761, 2063762, 2063763
Marian Rehak 2022-03-14 13:19:30 UTC Alias CVE-2022-0959
Summary pgadmin: Unrestricted file upload in pgAdmin CVE-2022-0959 pgadmin: Unrestricted file upload in pgAdmin
Marian Rehak 2022-03-14 14:09:04 UTC Blocks 2063861
Product Security DevOps Team 2022-03-14 17:02:01 UTC Resolution --- UPSTREAM
Status NEW CLOSED
Last Closed 2022-03-14 17:02:01 UTC
Marian Rehak 2022-03-23 12:40:29 UTC Doc Text A malicious, but authorised and authenticated user can construct an HTTP request using their existing CSRF token and session cookie to manually upload files to any location that the operating system user account under which pgAdmin is running has permission to write.

Back to bug 2063759