CVE-2024-2044

EUVD-2024-1004
pgAdmin <= 8.3 is affected by a path-traversal vulnerability while deserializing users’ sessions in the session handling code. If the server is running on Windows, an unauthenticated attacker can load and deserialize remote pickle objects and gain code execution. If the server is running on POSIX/Linux, an authenticated attacker can upload pickle objects, deserialize them, and gain code execution.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
9.9 CRITICAL
NETWORK
LOW
LOW
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 99%
Affected Products (NVD)
VendorProductVersion
pgadminpgadmin_4
𝑥
< 8.4
𝑥
= Vulnerable software versions
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
VendorProductVersionSource
postgresqlpgadmin_4
𝑥
< 8.4
ADP
openSUSE logo
openSUSE / SLES Releases
openSUSE Product
Release
pgadmin4
suse enterprise desktop 15 SP6
4.30-150300.3.12.1
fixed
suse enterprise desktop 15 SP7
4.30-150300.3.12.1
fixed
suse enterprise sap 15 SP3
4.30-150300.3.12.1
fixed
suse enterprise sap 15 SP4
4.30-150300.3.12.1
fixed
suse enterprise sap 15 SP5
4.30-150300.3.12.1
fixed
suse enterprise sap 15 SP6
4.30-150300.3.12.1
fixed
suse enterprise sap 15 SP7
4.30-150300.3.12.1
fixed
suse enterprise server 15 SP2
4.1-150100.3.9.2
fixed
suse enterprise server 15 SP3
4.30-150300.3.12.1
fixed
suse enterprise server 15 SP4
4.30-150300.3.12.1
fixed
suse enterprise server 15 SP5
4.30-150300.3.12.1
fixed
suse enterprise server 15 SP6
4.30-150300.3.12.1
fixed
suse enterprise server 15 SP7
4.30-150300.3.12.1
fixed
pgadmin4-doc
suse enterprise desktop 15 SP6
4.30-150300.3.12.1
fixed
suse enterprise desktop 15 SP7
4.30-150300.3.12.1
fixed
suse enterprise sap 15 SP3
4.30-150300.3.12.1
fixed
suse enterprise sap 15 SP4
4.30-150300.3.12.1
fixed
suse enterprise sap 15 SP5
4.30-150300.3.12.1
fixed
suse enterprise sap 15 SP6
4.30-150300.3.12.1
fixed
suse enterprise sap 15 SP7
4.30-150300.3.12.1
fixed
suse enterprise server 15 SP2
4.1-150100.3.9.2
fixed
suse enterprise server 15 SP3
4.30-150300.3.12.1
fixed
suse enterprise server 15 SP4
4.30-150300.3.12.1
fixed
suse enterprise server 15 SP5
4.30-150300.3.12.1
fixed
suse enterprise server 15 SP6
4.30-150300.3.12.1
fixed
suse enterprise server 15 SP7
4.30-150300.3.12.1
fixed
pgadmin4-web
suse enterprise desktop 15 SP6
4.30-150300.3.12.1
fixed
suse enterprise desktop 15 SP7
4.30-150300.3.12.1
fixed
suse enterprise sap 15 SP3
4.30-150300.3.12.1
fixed
suse enterprise sap 15 SP4
4.30-150300.3.12.1
fixed
suse enterprise sap 15 SP5
4.30-150300.3.12.1
fixed
suse enterprise sap 15 SP6
4.30-150300.3.12.1
fixed
suse enterprise sap 15 SP7
4.30-150300.3.12.1
fixed
suse enterprise server 15 SP2
4.1-150100.3.9.2
fixed
suse enterprise server 15 SP3
4.30-150300.3.12.1
fixed
suse enterprise server 15 SP4
4.30-150300.3.12.1
fixed
suse enterprise server 15 SP5
4.30-150300.3.12.1
fixed
suse enterprise server 15 SP6
4.30-150300.3.12.1
fixed
suse enterprise server 15 SP7
4.30-150300.3.12.1
fixed
system-user-pgadmin
suse enterprise desktop 15 SP6
8.5-150600.1.6
fixed
suse enterprise sap 15 SP6
8.5-150600.1.6
fixed
suse enterprise server 15 SP6
8.5-150600.1.6
fixed