First published: Mon Sep 23 2024(Updated: )
pgAdmin versions 8.11 and earlier are vulnerable to a security flaw in OAuth2 authentication. This vulnerability allows an attacker to potentially obtain the client ID and secret, leading to unauthorized access to user data.
Credit: f86ef6dc-4d3a-42ad-8f28-e6d5547a5007 f86ef6dc-4d3a-42ad-8f28-e6d5547a5007
Affected Software | Affected Version | How to fix |
---|---|---|
pip/pgadmin4 | <8.12 | 8.12 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-9014 has been classified as a high severity vulnerability.
To fix CVE-2024-9014, upgrade to pgAdmin version 8.12 or later.
The impact of CVE-2024-9014 includes the potential for unauthorized access to user data due to exposed OAuth2 credentials.
pgAdmin versions 8.11 and earlier are affected by CVE-2024-9014.
Yes, CVE-2024-9014 specifically affects the OAuth2 authentication method in pgAdmin.