Advisory on PostgreSQL Critical XSS Vulnerability and MFA Bypass Issue
Hello Linux users,
Two critical security vulnerabilities were found in pgAdmin, the open-source administration tool for PostgreSQL. These flaws affect the tool's cross-site scripting and multi-factor authentication features, allowing attackers to compromise your critical systems and steal your sensitive data.
Read on to learn how to secure your systems against these dangerous bugs. You’ll also get updates on other issues impacting your open-source programs and applications that threaten your sensitive information and system security.
If you gained valuable information from reading today’s newsletter, please share it with a fellow security geek. Do you have a Linux security-related topic you'd like to cover for our audience? We welcome contributions from enthusiastic, insightful community members who share our love for Linux and security!
Stay safe out there,

PostgreSQLThe DiscoveryTwo critical security vulnerabilities were found in pgAdmin, the open-source administration tool for PostgreSQL. These flaws affect the tool's cross-site scripting and multi-factor authentication features. |
apache2The DiscoveryDistros continue releasing updates addressing several recently identified vulnerabilities in the widely used Apache HTTP Server. These flaws involve the mishandling of inputs and the potential to inject malicious code. Another bug impacts the Apache HTTP Server's HTTP/2 module and could overwhelm the server with endless data streams, leading to denial of service attacks. |
ChromiumThe DiscoveryHave you updated to secure your systems against severe vulnerabilities recently identified in Chromium, the open-source web browser project providing the vast majority of code for Google Chrome? These flaws include a critical Type Confusion vulnerability in the ANGLE graphics layer engine, an out-of-bounds read in the V8 API, and a use-after-free condition in the Dawn implementation of the WebGPU standard. |



