PT-2024-36724 · Pghoard · Pghoard

·

CVE-2024-56142

·

Published

2024-12-17

·

Updated

2026-07-07

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions pghoard versions prior to 2.2.2a
Description A vulnerability has been discovered in pghoard that could allow an attacker to acquire disk access with privileges equivalent to those of pghoard, allowing for unintended path traversal. Depending on the permissions or privileges assigned to pghoard, this could allow disclosure of sensitive information.
Recommendations To resolve the issue, users are advised to upgrade to a version after 2.2.2a. At the moment, there are no known workarounds for this vulnerability.

Exploit

Fix

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2024-56142
GHSA-M9HC-VXJJ-4X6Q
PYSEC-2026-1778

Affected Products

Pghoard