
ankane/pghero
Releases89
Frequency1 month 2 weeks
Last Release
Stars8.88K
A performance dashboard for Postgres
CVE History
| CVE | Published | CVSS v3 | CVSS v2 |
|---|---|---|---|
| 7.5 HIGH | — | ||
PgHero before 3.1.0 allows Information Disclosure via EXPLAIN because query results may be present in an error message. (Depending on database user privileges, this may only be information from the database, or may be information from file contents on the database server.) | |||
| 8.1 HIGH | 5.8 MEDIUM | ||
The PgHero gem through 2.6.0 for Ruby allows CSRF. | |||