File _patchinfo of Package patchinfo.38248

<patchinfo incident="38248">
  <issue tracker="cve" id="2024-4068"/>
  <issue tracker="cve" id="2025-27152"/>
  <issue tracker="cve" id="2023-1907"/>
  <issue tracker="bnc" id="1234840">VUL-0: CVE-2023-1907: pgadmin4: users authenticated simultaneously via LDAP may be attached to the wrong session</issue>
  <issue tracker="bnc" id="1239308">VUL-0: CVE-2025-27152: pgadmin4: axios: requests sent to absolute URL even when baseURL is set, leading to possible SSRF and credential leakage</issue>
  <issue tracker="bnc" id="1224295">VUL-0: CVE-2024-4068: pgadmin4: the npm package `braces` fails to limit the number of characters it can handle, which could lead to Memory Exhaustion</issue>
  <packager>alarrosa</packager>
  <rating>important</rating>
  <category>security</category>
  <summary>Security update for pgadmin4</summary>
  <description>This update for pgadmin4 fixes the following issues:

- CVE-2025-27152: Fixed SSRF and creadential leakage due to requests sent to absolute URL even when baseURL is set (bsc#1239308)
- CVE-2023-1907: Fixed an issue which could result in users being authenticated in another user's session if two users authenticate simultaneously via ldap (bsc#1234840)
- CVE-2024-4068: Fixed a possible memory exhaustion (bsc#1224295)
</description>
</patchinfo>
openSUSE Build Service is sponsored by