PT-2024-6396 · Pgadmin+1 · Pgadmin+1

Published

2024-09-23

·

Updated

2025-11-27

·

CVE-2024-9014

CVSS v3.1

9.9

Critical

VectorAV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions pgAdmin versions 8.11 and earlier
Description The issue is related to a security flaw in OAuth2 authentication, allowing an attacker to potentially obtain the client ID and secret, leading to unauthorized access to user data. The vulnerability is associated with insufficient protection of registration data.
Recommendations For pgAdmin versions 8.11 and earlier, consider disabling OAuth2 authentication until a patch is available. Restrict access to sensitive data to minimize the risk of exploitation. Avoid using the client id and client secret parameters in the affected OAuth2 authentication flow until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Insufficiently Protected Credentials

Weakness Enumeration

Related Identifiers

ALT-PU-2025-6924
ALT-PU-2025-7344
ALT-PU-2025-9506
ALT-PU-2025-9551
BDU:2024-07481
CVE-2024-9014
GHSA-JM9X-RX9X-WPQJ
OPENSUSE-SU-2024_3771-1
OPENSUSE-SU-2025:14983-1
SUSE-SU-2024:3771-1

Affected Products

Pgadmin
Suse