CVE-2024-6238: pgAdmin 4 Installation Directory permission issue
pgAdmin <= 8.8 has an installation Directory permission issue. Because of this issue, attackers can gain unauthorised access to the installation directory on the Debian or RHEL 8 platforms.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
pgAdmin 4to a version that resolves this vulnerability.Fixed in 8.8
Event History
Frequently Asked Questions
What is the severity of CVE-2024-6238?
CVE-2024-6238 is classified as a medium severity vulnerability due to its potential to allow unauthorized access.
How do I fix CVE-2024-6238?
To fix CVE-2024-6238, ensure the installation directory permissions are set correctly to restrict unauthorized access.
Which versions of pgAdmin are affected by CVE-2024-6238?
CVE-2024-6238 affects pgAdmin versions up to and including 8.8.
On which platforms does CVE-2024-6238 exist?
CVE-2024-6238 exists on Debian and RHEL 8 platforms.
What is the nature of the vulnerability in CVE-2024-6238?
CVE-2024-6238 involves an installation directory permission issue that can be exploited by attackers.