¡¾Îó²îͨ¸æ¡¿pgAdmin 4 Ô¶³ÌÏÂÁîÖ´ÐÐÎó²î(CVE-2025-13780)
Ðû²¼Ê±¼ä 2025-12-17Ò»¡¢Îó²î¸ÅÊö
Îó²îÃû³Æ | pgAdmin 4 Ô¶³ÌÏÂÁîÖ´ÐÐÎó²î | ||
CVE ID | CVE-2025-13780 | ||
Îó²îÀàÐÍ | RCE | ·¢Ã÷ʱ¼ä | 2025-12-17 |
Îó²îÆÀ·Ö | 9.1 | Îó²îÆ·¼¶ | ÑÏÖØ |
¹¥»÷ÏòÁ¿ | ÍøÂç | ËùÐèȨÏÞ | µÍ |
ʹÓÃÄÑ¶È | µÍ | Óû§½»»¥ | ²»ÐèÒª |
PoC/EXP | ÒѹûÕæ | ÔÚҰʹÓà | δ·¢Ã÷ |
pgAdminÊÇÒ»¸öÓÃÓÚÖÎÀíºÍ¿ª·¢PostgreSQLÊý¾Ý¿âµÄ¿ªÔ´Í¼Ðλ¯¹¤¾ß¡£¡£¡£ËüÌṩÁËÒ»¸öÓû§ÓѺõĽçÃæ£¬£¬£¬£¬ÓÃÓÚÖ´ÐÐSQLÅÌÎÊ¡¢ÖÎÀíÊý¾Ý¿â¹¤¾ß¡¢Éó²éÊý¾Ý¿â¹¤¾ßµÄ½á¹¹¡¢ÌìÉú±¨±íºÍ±¸·Ý/»Ö¸´Êý¾Ý¿âµÈ²Ù×÷¡£¡£¡£pgAdminÖ§³Ö¶àÖÖ²Ù×÷ϵͳ£¬£¬£¬£¬°üÀ¨Windows¡¢macOSºÍLinux£¬£¬£¬£¬²¢ÇÒ¿ÉÒÔͨ¹ýWebä¯ÀÀÆ÷»á¼û£¬£¬£¬£¬±ãÓÚÔ¶³ÌÖÎÀí¡£¡£¡£ËüÆÕ±éÓ¦ÓÃÓÚÊý¾Ý¿âÖÎÀíÔ±¡¢¿ª·¢Ö°Ô±ºÍÊý¾ÝÆÊÎöʦÖУ¬£¬£¬£¬Ö§³ÖPostgreSQLµÄËùÓй¦Ð§²¢¼ò»¯ÁËÊý¾Ý¿âÖÎÀíʹÃü¡£¡£¡£
2025Äê12ÔÂ17ÈÕ£¬£¬£¬£¬918²©ÌìÌü¯ÍÅVSRC¼à²âµ½pgAdmin 4ÖеÄÒ»¸öÔ¶³ÌÏÂÁîÖ´ÐÐÎó²î¡£¡£¡£¸ÃÎó²î·ºÆðÔÚPLAIN»Ö¸´ÔªÏÂÁî¹ýÂËÆ÷ÖУ¬£¬£¬£¬¸Ã¹ýÂËÆ÷ÊÇΪÐÞ¸´CVE-2025-12762¶øÒýÈëµÄ¡£¡£¡£¸Ã¹ýÂËÆ÷δÄÜ׼ȷʶ±ðÒÔUTF-8×Ö½Ú˳Ðò±ê¼Ç£¨EF BB BF£©»òÆäËûÌØÊâ×Ö½ÚÐòÁпªÍ·µÄSQLÎļþÖеÄÔªÏÂÁî¡£¡£¡£¹ýÂËÆ÷ʹÓõÄhas_meta_commands()º¯Êýͨ¹ýÕýÔò±í´ïʽɨÃèÔʼ×Ö½Ú£¬£¬£¬£¬µ«Î´Äܽ«ÕâЩ×Ö½ÚÊÓΪ¿ÉºöÂÔ£¬£¬£¬£¬´Ó¶øµ¼ÖÂÔªÏÂÁÈç\\!£©Î´±»¼ì²âµ½¡£¡£¡£µ±pgAdminͨ¹ýpsql fileÏÂÁîŲÓÃSQLÎļþʱ£¬£¬£¬£¬psql»áÈ¥³ýÕâЩ×Ö½Ú²¢Ö´ÐÐÆäÖеÄÏÂÁ£¬£¬£¬´Ó¶ø¿ÉÄܵ¼ÖÂÔ¶³ÌÏÂÁîÖ´ÐС£¡£¡£
¶þ¡¢Ó°Ïì¹æÄ£
pgAdmin 4 < 9.11
Èý¡¢Çå¾²²½·¥
3.1 Éý¼¶°æ±¾
ÏÂÔØÁ´½Ó£ºhttps://github.com/pgadmin-org/pgadmin4/
3.2 ÔÝʱ²½·¥
ÔÝÎÞ¡£¡£¡£


¾©¹«Íø°²±¸11010802024551ºÅ