PT-2024-36724 · Pghoard · Pghoard

Jserran1

·

Published

2024-12-17

·

Updated

2024-12-18

·

CVE-2024-56142

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions pghoard versions prior to 2.2.2a
Description A vulnerability has been discovered in pghoard that could allow an attacker to acquire disk access with privileges equivalent to those of pghoard, allowing for unintended path traversal. Depending on the permissions or privileges assigned to pghoard, this could allow disclosure of sensitive information.
Recommendations To resolve the issue, users are advised to upgrade to a version after 2.2.2a. At the moment, there are no known workarounds for this vulnerability.

Exploit

Fix

Path traversal

Weakness Enumeration

Related Identifiers

CVE-2024-56142
GHSA-M9HC-VXJJ-4X6Q

Affected Products

Pghoard