Re: Vulnerabilities with the components used along with pgAdmin 4.18 - Mailing list pgadmin-support

From Dave Page
Subject Re: Vulnerabilities with the components used along with pgAdmin 4.18
Date
Msg-id CA+OCxoyf-6+r14GmnmFkCN2=BRAJx1t+4eD+d2XWeMZBw3BHTQ@mail.gmail.com
Whole thread Raw
In response to Vulnerabilities with the components used along with pgAdmin 4.18  ("Joel Mariadasan (jomariad)" <jomariad@cisco.com>)
List pgadmin-support
Hi

On Fri, Mar 27, 2020 at 11:02 AM Joel Mariadasan (jomariad) <jomariad@cisco.com> wrote:

Hi,

 

We are using pgAdmin 4(version 4.18) that is bundled along with Postgres 12.

 

We notice that version 4.18 of pgAdmin packages the following components that has some open vulnerabilities.

 

Read component, version, vulnerabilities:

python 3.7.4   https://www.cvedetails.com/vulnerability-list/vendor_id-10210/Python.html

sqlite     3.28.0   https://www.cvedetails.com/vulnerability-list/vendor_id-9237/Sqlite.html

zlib        1.2.8   https://www.cvedetails.com/vulnerability-list/vendor_id-72/product_id-1820/GNU-Zlib.html

curl        7.65.3  https://curl.haxx.se/docs/vuln-7.65.3.html

expat    2.2.7   https://www.cvedetails.com/vulnerability-list/vendor_id-12037/product_id-22545/Libexpat-Expat.html

openssl 1.1.1c    https://www.cvedetails.com/vulnerability-list/vendor_id-217/product_id-383/Openssl-Openssl.html

openssl 1.1.1d  https://www.cvedetails.com/vulnerability-list/vendor_id-217/product_id-383/Openssl-Openssl.html

 

 

We are using pgAdmin to administer our Database in a customer environment.

We have the following queries:

 

  1. Any open vulnerability with the above mentioned component versions that we should be worried about?
Please update to the latest release (4.20 as of today - PostgreSQL installer updates should come soon). 
 
  1. Is there any roadmap to upgrade the above components used in pgAdmin tool.
We continually audit bundled Python and JS components in pgAdmin, and regularly update the other components to the latest versions. Some may lag slightly behind if they're dependencies of other dependencies, e.g. some of those listed are part of the upstream Python release).

 

 

 

Joel Mariadasan

ENGINEER.SOFTWARE ENGINEERING

jomariad@cisco.com  

Mobile: +91 8197530175

Cisco Systems (India) Private Limited

Cessna Business Park, Kadubeesanahalli

Varthur Hobli, Sarjapur Marathalli ORR

Bangalore

Karnataka

560 103

India

This email may contain confidential and privileged material for the sole use of the intended recipient. Any review, use, distribution or disclosure by others is strictly prohibited. If you are not the intended recipient (or authorized to receive for the recipient), please contact the sender by reply email and delete all copies of this message.

Update Profile - Unsubscribe - Privacy

Please click here for Company Registration

 

 



--
Dave Page
Blog: http://pgsnake.blogspot.com
Twitter: @pgsnake

EnterpriseDB UK: http://www.enterprisedb.com
The Enterprise PostgreSQL Company
Attachment

pgadmin-support by date:

Previous
From: Toomas Kristin
Date:
Subject: PGAdmin integration with IAM authentication
Next
From: George Weaver
Date:
Subject: Starting just the pgAdmin server