¡¾·ì϶¹«¸æ¡¿pgAdmin 4 Ô¶³ÌºÅÁîÖ´Ðзì϶(CVE-2025-13780)
°ä²¼¹¦·ò 2025-12-17Ò»¡¢·ì϶¸ÅÊö
·ìϼûû³Æ | pgAdmin 4 Ô¶³ÌºÅÁîÖ´Ðзì϶ | ||
CVE ID | CVE-2025-13780 | ||
·ì϶ÀàÐÍ | RCE | ·¢ÏÖ¹¦·ò | 2025-12-17 |
·ì϶ÆÀ·Ö | 9.1 | ·ì϶µÈ¼¶ | ÑϳÁ |
¹¥»÷ÏòÁ¿ | ÍøÂç | ËùÐèȨÏÞ | µÍ |
ÀûÓÃÄÑ¶È | µÍ | Óû§½»»¥ | ²»±ØÒª |
PoC/EXP | Òѹ«¿ª | ÔÚÒ°ÀûÓà | δ·¢ÏÖ |
pgAdminÊÇÒ»¸öÓÃÓÚÖÎÀíºÍ¿ª·¢PostgreSQLÊý¾Ý¿âµÄ¿ªÔ´Í¼Ðλ¯¹¤¾ß¡£ËüÌṩÁËÒ»¸öÓû§¶ØÄÀµÄ½çÃæ£¬ÓÃÓÚÖ´ÐÐSQL²éÎÊ¡¢ÖÎÀíÊý¾Ý¿â¶ÔÏ󡢲鿴Êý¾Ý¿â¶ÔÏóµÄ½á¹¹¡¢ÌìÉú±¨±íºÍ±¸·Ý/¸´ÔÊý¾Ý¿âµÈ²Ù×÷¡£pgAdminÖ§³Ö¶àÖÖ²Ù×÷ϵͳ£¬Ô̺¬Windows¡¢macOSºÍLinux£¬²¢ÇÒÄܹ»Í¨¹ýWebä¯ÀÀÆ÷½Ó¼û£¬±ãÓÚÔ¶³ÌÖÎÀí¡£Ëü¿í·ºÀûÓÃÓÚÊý¾Ý¿âÖÎÀíÔ±¡¢¿ª·¢ÈËÔ±ºÍÊý¾Ý·ÖÎöʦÖУ¬Ö§³ÖPostgreSQLµÄËùÓÐÖ°Äܲ¢¼ò»¯ÁËÊý¾Ý¿âÖÎÀí¹¤×÷¡£
2025Äê12ÔÂ17ÈÕ£¬GA»Æ½ð¼×¼¯ÍÅVSRC¼à²âµ½pgAdmin 4ÖеÄÒ»¸öÔ¶³ÌºÅÁîÖ´Ðзì϶¡£¸Ã·ì϶³Ê´Ë¿ÌPLAIN¸´ÔÔªºÅÁî¹ýÂËÆ÷ÖУ¬¸Ã¹ýÂËÆ÷ÊÇΪ½¨¸´CVE-2025-12762¶øÒýÈëµÄ¡£¸Ã¹ýÂËÆ÷δÄÜÕýÈ·¼ø±ðÒÔUTF-8×Ö½Ú°¤´ÎÏóÕ÷£¨EF BB BF£©»òÆäËûÌØÊâ×Ö½ÚÐòÁпªÍ·µÄSQLÎļþÖеÄÔªºÅÁî¡£¹ýÂËÆ÷ʹÓõÄhas_meta_commands()º¯Êýͨ¹ýÕýÔò±í°×ʽɨÃèÔʼ×Ö½Ú£¬µ«Î´Äܽ«ÕâЩ×Ö½ÚÊÓΪ¿ÉºöÂÔ£¬´Ó¶øµ¼ÖÂÔªºÅÁÈç\\!£©Î´±»¼ì²âµ½¡£µ±pgAdminͨ¹ýpsql fileºÅÁîŲÓÃSQLÎļþʱ£¬psql»áÈ¥³ýÕâЩ×Ö½Ú²¢Ö´ÐÐÆäÖеĺÅÁ´Ó¶ø¿ÉÄܵ¼ÖÂÔ¶³ÌºÅÁîÖ´ÐС£
¶þ¡¢Ó°ÏìÁìÓò
pgAdmin 4 < 9.11
Èý¡¢°²È«´ëÊ©
3.1 Éý¼¶°æ±¾
ÏÂÔØÁ´½Ó£ºhttps://github.com/pgadmin-org/pgadmin4/
3.2 һʱ´ëÊ©
ÔÝÎÞ¡£


¾©¹«Íø°²±¸11010802024551ºÅ