pgAdmin 9.18 fixes four CVEs, including an auth bypass
pgAdmin 4 v9.18 closes an authentication bypass and two connection-string injections that redirect the connection, and the exported password, to a host of the caller's choosing.
Contributing writer
Software engineer, BSc First Class Honours in Computing and Information Systems. Writes about the JVM, build tooling and the parts of a release note that actually change behaviour.
pgAdmin 4 v9.18 closes an authentication bypass and two connection-string injections that redirect the connection, and the exported password, to a host of the caller's choosing.
A process for tracking, investigating and disclosing model behaviour, plus six cases observed over the last six months.