CVE-2024-9014

EUVD-2024-2825
pgAdmin versions 8.11 and earlier are vulnerable to a security flaw in OAuth2 authentication. This vulnerability allows an attacker to potentially obtain the client ID and secret, leading to unauthorized access to user data.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
9.9 CRITICAL
NETWORK
LOW
LOW
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 99%
Affected Products (NVD)
VendorProductVersion
pgadminpgadmin_4
𝑥
< 8.12
𝑥
= Vulnerable software versions
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
VendorProductVersionSource
postgresqlpgadmin_4
𝑥
< 8.12
ADP
openSUSE logo
openSUSE / SLES Releases
openSUSE Product
Release
pgadmin4
suse enterprise desktop 15 SP6
8.5-150600.3.6.1
fixed
suse enterprise desktop 15 SP7
8.5-150600.3.6.1
fixed
suse enterprise sap 15 SP6
8.5-150600.3.6.1
fixed
suse enterprise sap 15 SP7
8.5-150600.3.6.1
fixed
suse enterprise server 15 SP6
8.5-150600.3.6.1
fixed
suse enterprise server 15 SP7
8.5-150600.3.6.1
fixed
pgadmin4-doc
suse enterprise desktop 15 SP6
8.5-150600.3.6.1
fixed
suse enterprise desktop 15 SP7
8.5-150600.3.6.1
fixed
suse enterprise sap 15 SP6
8.5-150600.3.6.1
fixed
suse enterprise sap 15 SP7
8.5-150600.3.6.1
fixed
suse enterprise server 15 SP6
8.5-150600.3.6.1
fixed
suse enterprise server 15 SP7
8.5-150600.3.6.1
fixed
system-user-pgadmin
suse enterprise desktop 15 SP6
8.5-150600.3.6.1
fixed
suse enterprise desktop 15 SP7
8.5-150600.3.6.1
fixed
suse enterprise sap 15 SP6
8.5-150600.3.6.1
fixed
suse enterprise sap 15 SP7
8.5-150600.3.6.1
fixed
suse enterprise server 15 SP6
8.5-150600.3.6.1
fixed
suse enterprise server 15 SP7
8.5-150600.3.6.1
fixed