Improper Authentication in pgAdmin - CVE-2024-9014
Published: October 31, 2024 / Updated: February 21, 2025
Vulnerability identifier: #VU99562
CSH Severity: High
CVSS v4: 8.8 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2024-9014
CWE-ID: CWE-287
Exploitation vector: Remote access
Exploit availability:
Public exploit is available
Vulnerability details
The vulnerability allows a remote attacker to bypass authentication process.
The vulnerability exists due to an error in OAuth2 authentication. A remote attacker can obtain the client ID and secret and bypass authentication process.
Affected software
pgAdmin
SUSE Linux Enterprise Desktop 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise Server for SAP Applications 15
Python 3 Module
openSUSE Leap
Fedora
pgadmin4-desktop
system-user-pgadmin
pgadmin4-doc
pgadmin4-cloud
pgadmin4
pgadmin4-web-uwsgi
SUSE Linux Enterprise Desktop 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise Server for SAP Applications 15
Python 3 Module
openSUSE Leap
Fedora
pgadmin4-desktop
system-user-pgadmin
pgadmin4-doc
pgadmin4-cloud
pgadmin4
pgadmin4-web-uwsgi
How to mitigate CVE-2024-9014
Install updates from vendor's website.
pgAdmin - update to 8.12
pgadmin4-desktop - update to 8.5-150600.3.6.1
system-user-pgadmin - update to 8.5-150600.3.6.1
pgadmin4-doc - update to 8.5-150600.3.6.1
pgadmin4-cloud - update to 8.5-150600.3.6.1
pgadmin4 - update to 8.5-150600.3.6.1
pgadmin4-web-uwsgi - update to 8.5-150600.3.6.1
pgadmin4 - addressed in versions 8.9-3.fc40, 8.12-1.fc41
pgadmin4-desktop - update to 8.5-150600.3.6.1
system-user-pgadmin - update to 8.5-150600.3.6.1
pgadmin4-doc - update to 8.5-150600.3.6.1
pgadmin4-cloud - update to 8.5-150600.3.6.1
pgadmin4 - update to 8.5-150600.3.6.1
pgadmin4-web-uwsgi - update to 8.5-150600.3.6.1
pgadmin4 - addressed in versions 8.9-3.fc40, 8.12-1.fc41