216.73.216.233

CVE-2025-0218

· Published 07/01/2025 20:15 · Modified 11/02/2025 21:11

Labels: CVE-2025-0218 2025-01-07CVE-2025-0218CWE-330CWE-340f86ef6dc-4d3a-42ad-8f28-e6d5547a5007

Essential information

Published
07/01/2025 20:15
Modified
11/02/2025 21:11
Author
Creator
CVSS
5.5 MEDIUM (v3.1)
CISA KEV
No
CWE
CVSS vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

CVSS metrics

Description

When batch jobs are executed by pgAgent, a script is created in a temporary directory and then executed. In versions of pgAgent prior to 4.2.3, an insufficiently seeded random number generator is used when generating the directory name, leading to the possibility for a local attacker to pre-create the directory and thus prevent pgAgent from executing jobs, disrupting scheduled tasks.

NVD status

Status
Analyzed — CVE has had analysis completed and all data associations made.
Source
f86ef6dc-4d3a-42ad-8f28-e6d5547a5007
NVD
View on NVD

Affected products (CPE)

ProductCPE
pgadmin / pgagent cpe:2.3:a:pgadmin:pgagent:*:*:*:*:*:postgresql:*:*

References