{"id":"CVE-2018-16203","details":"PgpoolAdmin 4.0 and earlier allows remote attackers to bypass the login authentication and obtain the administrative privilege of the PostgreSQL database via unspecified vectors.","modified":"2026-07-08T20:30:58.592940Z","published":"2019-01-09T23:29:05.027Z","references":[{"type":"ADVISORY","url":"https://jvn.jp/en/jp/JVN13199224/index.html"},{"type":"ADVISORY","url":"https://pgpool.net/mediawiki/index.php/Main_Page"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/pgpool/pgpooladmin","events":[{"introduced":"0"},{"last_affected":"d620c09392b438ac750377cb1b3d7a60fb61d125"}],"database_specific":{"cpe":"cpe:2.3:a:pgpool:pgpooladmin:*:*:*:*:*:*:*:*","extracted_events":[{"introduced":"0"},{"last_affected":"4.0"}],"source":"CPE_RANGE"}}],"versions":["V4_0_0_RPM","V4_0_0","V3_7_1_RPM","V3_7_1","V3_7_0_RPM","V3_7_0","V3_7_RC1_RPM","V3_7_RC1","V3_6_2_RPM","V3_6_2","V3_6_1_RPM","V3_6_1","V3_6_0_RPM","V3_6_0","V3_5_3_RPM","V3_5_3","V3_5_2_RPM","V3_5_2","V3_5_1","V3_4_0","V3_4_0_RC2","V3_4_0_RC1","V3_4_0_BETA2","V3_4_0_ALPHA1","V3_3_1","V3_3","V3_3_RC1","V3_2_2","V3_2_1","V3_1_1","V3_0_3","V3_0_1","V3_0_0","V3_0_0_BETA2","V3_0_0_BETA1","V2_3_0","V2_2_0","V2_2_0_BETA1","V2_1_0_BETA1","V2_0_0_BETA1","V1_0_0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2018-16203.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"}]}