pgAdmin versions 8.11 and earlier are vulnerable to a security flaw in OAuth2 authentication. This vulnerability allows an attacker to potentially obtain the client ID and secret, leading to unauthorized access to user data.
Metrics
Affected Vendors & Products
References
Link | Providers |
---|---|
https://github.com/pgadmin-org/pgadmin4/issues/7945 |
History
Mon, 23 Sep 2024 20:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Postgresql
Postgresql pgadmin 4 |
|
Weaknesses | CWE-522 | |
CPEs | cpe:2.3:a:postgresql:pgadmin_4:*:*:*:*:*:*:*:* | |
Vendors & Products |
Postgresql
Postgresql pgadmin 4 |
|
Metrics |
ssvc
|
Mon, 23 Sep 2024 17:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | pgAdmin versions 8.11 and earlier are vulnerable to a security flaw in OAuth2 authentication. This vulnerability allows an attacker to potentially obtain the client ID and secret, leading to unauthorized access to user data. | |
Title | OAuth2 client id and secret exposed through the web browser in pgAdmin 4 | |
References |
| |
Metrics |
cvssV3_1
|
MITRE
Status: PUBLISHED
Assigner: PostgreSQL
Published: 2024-09-23T17:04:00.264Z
Updated: 2024-09-23T19:21:22.348Z
Reserved: 2024-09-19T18:00:05.741Z
Link: CVE-2024-9014
Vulnrichment
Updated: 2024-09-23T19:21:17.669Z
NVD
Status : Awaiting Analysis
Published: 2024-09-23T17:15:14.000
Modified: 2024-09-26T13:32:55.343
Link: CVE-2024-9014
Redhat
No data.