PT-2024-2008 · Pgadmin+2 · Pgadmin+2

Abdel Adim Oisfi

+3

·

Published

2024-03-07

·

Updated

2024-09-19

·

CVE-2024-2044

CVSS v3.1

9.9

Critical

VectorAV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions pgAdmin versions prior to 8.4
Description The issue is related to a path-traversal vulnerability in the session handling code of pgAdmin, which can lead to unsafe deserialization and remote code execution. This vulnerability can be exploited by an unauthenticated attacker on Windows or an authenticated attacker on POSIX/Linux systems, allowing them to gain code execution. The vulnerability is associated with the incorrect serialization of the pga4 session cookie file.
Recommendations For pgAdmin versions prior to 8.4, update to version 8.4 or later to resolve the issue. As a temporary workaround, consider restricting access to the session handling code to minimize the risk of exploitation. Avoid using the pga4 session cookie file until the issue is resolved. At the moment, there is no other information about additional mitigation measures.

Exploit

Fix

Path traversal

Deserialization of Untrusted Data

Weakness Enumeration

Related Identifiers

BDU:2024-01869
CVE-2024-2044
GHSA-RJ98-CRF4-G69W
OPENSUSE-SU-2024:13843-1
OPENSUSE-SU-2024_1340-1
SUSE-SU-2024:1340-1
SUSE-SU-2024_1340-1

Affected Products

Pgadmin
Red Os
Suse