PT-2023-10828 · Blue Yonder · Postgraas Server

CVE-2018-25088

·

Published

2023-07-18

·

Updated

2026-06-29

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Blue Yonder postgraas server versions up to 2.0.0b2
Description A critical issue was found in the PostgreSQL Backend Handler component, specifically in the create pg connection/create postgres db function of the postgraas server/backends/postgres cluster/postgres cluster driver.py file. This issue leads to sql injection.
Recommendations To address this issue, upgrade to version 2.0.0. As a temporary workaround, consider restricting access to the vulnerable postgraas server component to minimize the risk of exploitation.

Fix

SQL injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2018-25088
GHSA-VGHM-8CJP-HJW6
PYSEC-2026-460

Affected Products

Postgraas Server