CVE-2024-9014: OAuth2 client id and secret exposed through the web browser in pgAdmin 4
Published Sep 23, 2024
·Updated
pgAdmin versions 8.11 and earlier are vulnerable to a security flaw in OAuth2 authentication. This vulnerability allows an attacker to potentially obtain the client ID and secret, leading to unauthorized access to user data.
Affected Software
2 affected componentsFixes available
pip/pgadmin4<8.12
8.12
pgAdmin Pgadmin 4 Postgresql<8.12
Event History
Sep 23, 2024
CVE Published
via MITRE·05:04 PM
Data Sourced
via MITRE·05:04 PM
DescriptionSeverity
Data Sourced
via NVD·05:15 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·05:15 PM
Affected Software
Advisory Published
via GitHub·06:30 PM
Frequently Asked Questions
1
What is the severity of CVE-2024-9014?
CVE-2024-9014 has been classified as a high severity vulnerability.
2
How do I fix CVE-2024-9014?
To fix CVE-2024-9014, upgrade to pgAdmin version 8.12 or later.
3
What is the impact of CVE-2024-9014?
The impact of CVE-2024-9014 includes the potential for unauthorized access to user data due to exposed OAuth2 credentials.
4
Which versions of pgAdmin are affected by CVE-2024-9014?
pgAdmin versions 8.11 and earlier are affected by CVE-2024-9014.
5
Is CVE-2024-9014 specific to the OAuth2 method?
Yes, CVE-2024-9014 specifically affects the OAuth2 authentication method in pgAdmin.