Skip to content

Unsafe deserialization in DatabaseSchemaViewer

High
martinjw published GHSA-rfjh-m356-mpqf Oct 31, 2020

Package

No package listed

Affected versions

< 2.7.4.3

Patched versions

2.7.4.3

Description

Impact

DatabaseSchemaViewer is vulnerable to arbitrary code execution if a user is tricked into opening a specially crafted .dbschema file.

Patches

The patch was released in v2.7.4.3.

Workarounds

Do not open .dbschema files from untrusted sources.

Severity

High

CVE ID

CVE-2020-26207

Weaknesses

No CWEs

Credits