pgAdmin versions 8.11 and earlier are vulnerable to a security flaw in OAuth2 authentication. This vulnerability allows an attacker to potentially obtain the client ID and secret, leading to unauthorized access to user data.
History

Mon, 23 Sep 2024 20:30:00 +0000

Type Values Removed Values Added
First Time appeared Postgresql
Postgresql pgadmin 4
Weaknesses CWE-522
CPEs cpe:2.3:a:postgresql:pgadmin_4:*:*:*:*:*:*:*:*
Vendors & Products Postgresql
Postgresql pgadmin 4
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 23 Sep 2024 17:15:00 +0000

Type Values Removed Values Added
Description pgAdmin versions 8.11 and earlier are vulnerable to a security flaw in OAuth2 authentication. This vulnerability allows an attacker to potentially obtain the client ID and secret, leading to unauthorized access to user data.
Title OAuth2 client id and secret exposed through the web browser in pgAdmin 4
References
Metrics cvssV3_1

{'score': 9.9, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: PostgreSQL

Published: 2024-09-23T17:04:00.264Z

Updated: 2024-09-23T19:21:22.348Z

Reserved: 2024-09-19T18:00:05.741Z

Link: CVE-2024-9014

cve-icon Vulnrichment

Updated: 2024-09-23T19:21:17.669Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2024-09-23T17:15:14.000

Modified: 2024-09-26T13:32:55.343

Link: CVE-2024-9014

cve-icon Redhat

No data.