File _patchinfo of Package patchinfo.38248
<patchinfo incident="38248"> <issue tracker="cve" id="2024-4068"/> <issue tracker="cve" id="2025-27152"/> <issue tracker="cve" id="2023-1907"/> <issue tracker="bnc" id="1234840">VUL-0: CVE-2023-1907: pgadmin4: users authenticated simultaneously via LDAP may be attached to the wrong session</issue> <issue tracker="bnc" id="1239308">VUL-0: CVE-2025-27152: pgadmin4: axios: requests sent to absolute URL even when baseURL is set, leading to possible SSRF and credential leakage</issue> <issue tracker="bnc" id="1224295">VUL-0: CVE-2024-4068: pgadmin4: the npm package `braces` fails to limit the number of characters it can handle, which could lead to Memory Exhaustion</issue> <packager>alarrosa</packager> <rating>important</rating> <category>security</category> <summary>Security update for pgadmin4</summary> <description>This update for pgadmin4 fixes the following issues: - CVE-2025-27152: Fixed SSRF and creadential leakage due to requests sent to absolute URL even when baseURL is set (bsc#1239308) - CVE-2023-1907: Fixed an issue which could result in users being authenticated in another user's session if two users authenticate simultaneously via ldap (bsc#1234840) - CVE-2024-4068: Fixed a possible memory exhaustion (bsc#1224295) </description> </patchinfo>