Description
pgAdmin <= 8.4 is affected by a Remote Code Execution (RCE) vulnerability through the validate binary path API. This vulnerability allows attackers to execute arbitrary code on the server hosting PGAdmin, posing a severe risk to the database management system's integrity and the security of the underlying data.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-27jx-ffw8-xrqv | pgAdmin Remote Code Execution (RCE) vulnerability |
References
History
Mon, 17 Mar 2025 17:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Pgadmin pgadmin 4
|
|
| CPEs | cpe:2.3:a:pgadmin:pgadmin_4:*:*:*:*:*:postgresql:*:* | |
| Vendors & Products |
Pgadmin pgadmin
|
Pgadmin pgadmin 4
|
Fri, 14 Mar 2025 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Postgresql
Postgresql pgadmin 4 |
|
| Weaknesses | CWE-77 | |
| CPEs | cpe:2.3:a:postgresql:pgadmin_4:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Postgresql
Postgresql pgadmin 4 |
|
| Metrics |
ssvc
|
Thu, 13 Feb 2025 18:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | pgAdmin <= 8.4 is affected by a Remote Code Execution (RCE) vulnerability through the validate binary path API. This vulnerability allows attackers to execute arbitrary code on the server hosting PGAdmin, posing a severe risk to the database management system's integrity and the security of the underlying data. | pgAdmin <= 8.4 is affected by a Remote Code Execution (RCE) vulnerability through the validate binary path API. This vulnerability allows attackers to execute arbitrary code on the server hosting PGAdmin, posing a severe risk to the database management system's integrity and the security of the underlying data. |
Tue, 11 Feb 2025 16:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Fedoraproject
Fedoraproject fedora Pgadmin Pgadmin pgadmin |
|
| Weaknesses | NVD-CWE-noinfo | |
| CPEs | cpe:2.3:a:pgadmin:pgadmin:*:*:*:*:*:postgresql:*:* cpe:2.3:o:fedoraproject:fedora:39:*:*:*:*:*:*:* |
|
| Vendors & Products |
Fedoraproject
Fedoraproject fedora Pgadmin Pgadmin pgadmin |
Wed, 21 Aug 2024 23:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Status: PUBLISHED
Assigner: PostgreSQL
Published:
Updated: 2025-03-14T16:35:25.051Z
Reserved: 2024-03-30T03:46:32.060Z
Link: CVE-2024-3116
Updated: 2024-08-19T07:47:48.299Z
Status : Modified
Published: 2024-04-04T15:15:39.667
Modified: 2025-03-17T16:43:52.873
Link: CVE-2024-3116
No data.
OpenCVE Enrichment
No data.
Weaknesses
Github GHSA