PT-2024-9759 · Pgadmin+2 · Pgadmin+2

Published

2024-05-02

·

Updated

2025-04-17

·

CVE-2024-4215

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions pgAdmin versions <= 8.5
Description The issue exists due to the incorrect implementation of multi-factor authentication in the pgAdmin database management tool. This allows a remote attacker to gain unauthorized access to the application and execute arbitrary SQL code. An attacker with knowledge of a legitimate account's username and password may authenticate to the application and perform sensitive actions, such as managing files and executing SQL queries, regardless of the account's MFA enrollment status.
Recommendations For pgAdmin versions <= 8.5, update to a version that includes a fix for the multi-factor authentication bypass issue. As a temporary workaround, consider restricting access to sensitive actions within the application to minimize the risk of exploitation.

Fix

SQL injection

Weakness Enumeration

Related Identifiers

BDU:2024-11497
CVE-2024-4215
GHSA-2MVC-557G-5638
OPENSUSE-SU-2024:14052-1
OPENSUSE-SU-2024_2260-1
SUSE-SU-2024:2260-1

Affected Products

Pgadmin
Red Os
Suse