ankane/pghero

ankane/pghero

Releases89
Frequency1 month 2 weeks
Last Release
Stars8.88K
A performance dashboard for Postgres

CVE History

CVEPublishedCVSS v3CVSS v2
7.5 HIGH

PgHero before 3.1.0 allows Information Disclosure via EXPLAIN because query results may be present in an error message. (Depending on database user privileges, this may only be information from the database, or may be information from file contents on the database server.)

8.1 HIGH5.8 MEDIUM

The PgHero gem through 2.6.0 for Ruby allows CSRF.