PT-2024-36724 · Pghoard · Pghoard
Jserran1
·
Published
2024-12-17
·
Updated
2024-12-18
·
CVE-2024-56142
CVSS v3.1
6.5
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
pghoard versions prior to 2.2.2a
Description
A vulnerability has been discovered in pghoard that could allow an attacker to acquire disk access with privileges equivalent to those of pghoard, allowing for unintended path traversal. Depending on the permissions or privileges assigned to pghoard, this could allow disclosure of sensitive information.
Recommendations
To resolve the issue, users are advised to upgrade to a version after 2.2.2a.
At the moment, there are no known workarounds for this vulnerability.
Exploit
Fix
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Pghoard