S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
high·Misconfiguration·Updated Nov 26, 2024

Pgwatch2 DBs to Monitor Exposure Scanner

This scanner targets the Pgwatch2 web dashboard endpoint to detect misconfigurations that allow unauthenticated access to sensitive database monitoring data.

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsurl
CostFree
2.2k
Times Used
continuous scan runs
6.1k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
Detail

Pgwatch2 is an open-source database monitoring tool used by database administrators and IT teams to track performance metrics, query statistics, and health indicators of PostgreSQL databases. It provides real-time dashboards and alerts to help maintain database stability and efficiency. Organizations with large database infrastructures rely on it for proactive monitoring and troubleshooting. Proper configuration is essential to secure the monitoring environment.

The exposure vulnerability arises when the Pgwatch2 dashboard is accessible without authentication due to misconfigured access controls or network settings. This can happen if the dashboard is exposed to the internet or internal networks without proper restrictions. Attackers can exploit this to view sensitive database metrics and configurations.

Specifically, the vulnerability targets the Pgwatch2 web interface, typically hosted on a default port like 8080 or 3000. The scanner checks if the dashboard is accessible without authentication, revealing endpoints such as /dbs or /metrics that list monitored databases and their performance data.

If exploited, an attacker can gain unauthorized visibility into database performance, query patterns, and system health, which can be used to plan further attacks. This exposure can lead to data breaches, service disruption, or compliance violations, especially in regulated environments.

Solution Advice
  • Enable authentication on the Pgwatch2 dashboard using built-in mechanisms or reverse proxy.
  • Restrict network access to the dashboard using firewalls or VPNs to trusted IPs only.
  • Use HTTPS to encrypt traffic between clients and the dashboard.
  • Regularly audit dashboard configuration files for unintended exposure.
  • Implement role-based access control (RBAC) to limit user permissions.
  • Deploy a web application firewall (WAF) to block unauthorized access attempts.
  • Monitor logs for suspicious access patterns to the dashboard.
  • Update Pgwatch2 to the latest version to patch known security issues.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.