CVE-2024-3116: Remote Code Execution Vulnerability through the validate binary path API in pgAdmin 4
Published Apr 4, 2024
·Updated
pgAdmin <= 8.4 is affected by a Remote Code Execution (RCE) vulnerability through the validate binary path API. This vulnerability allows attackers to execute arbitrary code on the server hosting PGAdmin, posing a severe risk to the database management system's integrity and the security of the underlying data.
Affected Software
3 affected componentsFixes available
pip/pgadmin4<8.5
8.5
pgAdmin Pgadmin 4 Postgresql<=8.4
Fedoraproject Fedora=39
Event History
Apr 4, 2024
CVE Published
via MITRE·02:59 PM
Data Sourced
via MITRE·02:59 PM
DescriptionSeverity
Advisory Published
via GitHub·03:30 PM
Data Sourced
via GitHub·03:30 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-3116?
CVE-2024-3116 has a severe risk level as it allows remote code execution on affected servers.
2
How do I fix CVE-2024-3116?
To mitigate CVE-2024-3116, update pgAdmin to version 8.5 or later.
3
Which versions are affected by CVE-2024-3116?
CVE-2024-3116 affects pgAdmin versions up to and including 8.4.
4
What type of vulnerability is CVE-2024-3116?
CVE-2024-3116 is a remote code execution (RCE) vulnerability.
5
How can attackers exploit CVE-2024-3116?
Attackers can exploit CVE-2024-3116 through the validate binary path API to execute arbitrary code.