CVE-2025-0218
CVSS 3.1 Score 7.1 of 10 (high)
Details
Published Jan 7, 2025
Updated: Feb 11, 2025
CWE ID 340
CWE ID 330
Summary
CVE-2025-0218 is a vulnerability affecting pgAgent versions prior to 4.2.3. The issue lies in the way batch jobs are executed, where a script is created in a temporary directory and then executed. However, an insufficiently seeded random number generator is used when generating the directory name, creating an opportunity for a local attacker to pre-create the directory and prevent pgAgent from executing jobs, ultimately disrupting scheduled tasks.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Vendors
- Pgadmin