CVE-2025-0218
MEDIUMDescription
When batch jobs are executed by pgAgent, a script is created in a temporary directory and then executed. In versions of pgAgent prior to 4.2.3, an insufficiently seeded random number generator is used when generating the directory name, leading to the possibility for a local attacker to pre-create the directory and thus prevent pgAgent from executing jobs, disrupting scheduled tasks.
Is your site exposed to CVE-2025-0218?
Run a free security scan — no signup, results in seconds.
CVSS v3.1 Score
Weakness Type (CWE)
Affected Products
| Vendor | Product |
|---|---|
| pgadmin | pgagent |
References
Advisories & Patches
Other References
Frequently Asked Questions
What is CVE-2025-0218? +
How severe is CVE-2025-0218? +
What products are affected by CVE-2025-0218? +
How do I check if I'm vulnerable to CVE-2025-0218? +
Related Vulnerabilities
The application generates uploaded file names using a weak and predictable method based on the request timestamp. This allows a …
ATutor generates predictable email confirmation tokens due to the use of insufficiently random values in the account confirmation functionality. Due …
The devices are vulnerable to session hijacking due to insufficient entropy in its session ID generation algorithm. The session IDs …
RAGFlow is an open-source RAG (Retrieval-Augmented Generation) engine. In versions prior to 0.22.0, the use of an insecure key generation …
FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.213, attachment download tokens are generated using …
Apache::Session::Generate::ModUniqueId versions from 1.54 through 1.94 for Perl session ids are insecure. Apache::Session::Generate::ModUniqueId (added in version 1.54) uses the value …