Improper Authentication in pgAdmin - CVE-2024-9014

 

Improper Authentication in pgAdmin - CVE-2024-9014

Published: October 31, 2024 / Updated: February 21, 2025


Vulnerability identifier: #VU99562
CSH Severity: High
CVSS v4: 8.8 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2024-9014
CWE-ID: CWE-287
Exploitation vector: Remote access
Exploit availability: Public exploit is available

Vulnerability details

The vulnerability allows a remote attacker to bypass authentication process.

The vulnerability exists due to an error in OAuth2 authentication. A remote attacker can obtain the client ID and secret and bypass authentication process.


Affected software

pgAdmin
SUSE Linux Enterprise Desktop 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise Server for SAP Applications 15
Python 3 Module
openSUSE Leap
Fedora
pgadmin4-desktop
system-user-pgadmin
pgadmin4-doc
pgadmin4-cloud
pgadmin4
pgadmin4-web-uwsgi

How to mitigate CVE-2024-9014

Install updates from vendor's website.

pgAdmin - update to 8.12
pgadmin4-desktop - update to 8.5-150600.3.6.1
system-user-pgadmin - update to 8.5-150600.3.6.1
pgadmin4-doc - update to 8.5-150600.3.6.1
pgadmin4-cloud - update to 8.5-150600.3.6.1
pgadmin4 - update to 8.5-150600.3.6.1
pgadmin4-web-uwsgi - update to 8.5-150600.3.6.1
pgadmin4 - addressed in versions 8.9-3.fc40, 8.12-1.fc41

Links to Public Exploits and PoC-codes

External References

Related Security Bulletins