CVE-2024-9014
Severity CVSS v4.0:
Pending analysis
Type:
CWE-522
Insufficiently Protected Credentials
Publication date:
23/09/2024
Last modified:
26/09/2024
Description
pgAdmin versions 8.11 and earlier are vulnerable to a security flaw in OAuth2 authentication. This vulnerability allows an attacker to potentially obtain the client ID and secret, leading to unauthorized access to user data.
Impact
Base Score 3.x
9.90
Severity 3.x
CRITICAL