Alerts This Week
Warning Icon 1 714
Alerts This Week
Warning Icon 1 714

Fedora 41: 2025-49d6f62c0e critical: pgAdmin remote code execution

fedora
Calendar Grey April 27, 2025
Dist Fedora Esm H88
The latest update to pgAdmin 9.2 resolves critical security issues, such as potential remote code execution threats and cross-site scripting (XSS) vulnerabilities.
Update to pgadmin-9.2.

Summary

pgAdmin is the most popular and feature rich Open Source administration and development

platform for PostgreSQL, the most advanced Open Source database in the world.

Update Information:

Update to pgadmin-9.2.

Change Log

* Wed Apr 9 2025 Sandro Mani - 9.2-1 - Update to 9.2 * Wed Mar 12 2025 Sandro Mani - 9.1-2 - Fix azure-mgmt-subscription requirement * Mon Mar 10 2025 Sandro Mani - 9.1-1 - Update to 9.1 * Thu Feb 6 2025 Sandro Mani - 9.0-1 - Update to 9.0

References


[ 1 ] Bug #2357255 - CVE-2025-2945 pgadmin4: pgAdmin 4: Remote Code Execution in Query Tool and Cloud Deployment [fedora-41] https://bugzilla.redhat.com/show_bug.cgi?id=2357255 [ 2 ] Bug #2357257 - CVE-2025-2946 pgadmin4: Cross-Site Vulnerability(XSS) due to arbitrary HTML/JavaScript gets executed while query result rendering in Query Tool and View/Edit Data Tool of pgAdmin 4 [fedora-41] https://bugzilla.redhat.com/show_bug.cgi?id=2357257

Update Instructions

This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2025-49d6f62c0e' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label

Severity
critical
Lowest
Low
Medium
High
Critical

Name: pgadmin4
Product: Fedora 41
Version: 9.2
Release: 1.fc41
Summary: Administration tool for PostgreSQL

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here