CVE-2024-9014

Severity CVSS v4.0:
Pending analysis
Type:
CWE-522 Insufficiently Protected Credentials
Publication date:
23/09/2024
Last modified:
22/09/2025

Description

pgAdmin versions 8.11 and earlier are vulnerable to a security flaw in OAuth2 authentication. This vulnerability allows an attacker to potentially obtain the client ID and secret, leading to unauthorized access to user data.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:pgadmin:pgadmin_4:*:*:*:*:*:postgresql:*:* 8.12 (excluding)


References to Advisories, Solutions, and Tools