Vulnerability Description
pgAdmin versions 8.11 and earlier are vulnerable to a security flaw in OAuth2 authentication. This vulnerability allows an attacker to potentially obtain the client ID and secret, leading to unauthorized access to user data.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Pgadmin | Pgadmin 4 | < 8.12 |
Related Weaknesses (CWE)
References
- https://github.com/pgadmin-org/pgadmin4/issues/7945Issue Tracking
FAQ
What is CVE-2024-9014?
CVE-2024-9014 is a vulnerability with a CVSS score of 9.9 (CRITICAL). pgAdmin versions 8.11 and earlier are vulnerable to a security flaw in OAuth2 authentication. This vulnerability allows an attacker to potentially obtain the client ID and secret, leading to unauthori...
How severe is CVE-2024-9014?
CVE-2024-9014 has been rated CRITICAL with a CVSS base score of 9.9/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2024-9014?
Check the references section above for vendor advisories and patch information. Affected products include: Pgadmin Pgadmin 4.