Security update for pgadmin4
This update for pgadmin4 fixes the following issues: - CVE-2025-27152: Fixed SSRF and creadential leakage due to requests sent to absolute URL even when baseURL is set (bsc#1239308) - CVE-2023-1907: Fixed an issue which could result in users being authenticated in another user's session if two users authenticate simultaneously via ldap (bsc#1234840) - CVE-2024-4068: Fixed a possible memory exhaustion (bsc#1224295)
02 / AFFECTED SOFTWARE
Affected packages
03 / CONNECTIONS
Connected vulnerabilities
04 / EVIDENCE
Source records
This update for pgadmin4 fixes the following issues: - CVE-2025-27152: Fixed SSRF and creadential leakage due to requests sent to absolute URL even when baseURL is set (bsc#1239308) - CVE-2023-1907: Fixed an issue which could result in users being authenticated in another user's session if two users authenticate simultaneously via ldap (bsc#1234840) - CVE-2024-4068: Fixed a possible memory exhaustion (bsc#1224295)
05 / REFERENCES
Further evidence
- https://bugzilla.suse.com/1224295
- https://bugzilla.suse.com/1234840
- https://bugzilla.suse.com/1239308
- https://www.suse.com/security/cve/CVE-2023-1907
- https://www.suse.com/security/cve/CVE-2024-4068
- https://www.suse.com/security/cve/CVE-2025-27152
- https://www.suse.com/support/update/announcement/2025/suse-su-20251326-1/