Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

PgAdmin Installation Directory permission issue #7605

Closed
khushboovashi opened this issue Jun 20, 2024 · 4 comments
Closed

PgAdmin Installation Directory permission issue #7605

khushboovashi opened this issue Jun 20, 2024 · 4 comments
Assignees
Milestone

Comments

@khushboovashi
Copy link
Contributor

After installing PgAdmin, several directories, including 'bin', 'venv', and 'web', have 775 permissions.

@pravesh-sharma
Copy link
Contributor

Issue fixed. Tested candidate build.

Env:
OS - Rocky 8

@abergmann
Copy link

CVE-2024-6238 was assigned to this issue.

@abergmann
Copy link

According to the NVD description this issue affects all pgAdmin <= 8.8. Is this really the case?

Furthermore, is there a git commit fixing this issue that can be mentioned here?

@cfi-gb
Copy link

cfi-gb commented Jun 27, 2024

https://github.com/pgadmin-org/pgadmin4/blob/REL-8_9/docs/en_US/release_notes_8_9.rst seems to link to this as:

#7605 - Fix the permissions issue in the pgAdmin installation directory on Debian and RHEL-8 platforms (CVE-2024-6238).

Doing a diff between version 8.8 and 8.9 via REL-8_8...REL-8_9 indicates a few fixes between both releases related to permissions on Debian and RHEL:

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

No branches or pull requests

5 participants