|
|||
Rule General Information |
---|
Release Date: | 2024-10-15 | |
Rule Name: | pgAdmin OAuth2 Sensitive Information Leakage Vulnerability (CVE-2024-9014) | |
Severity: | ||
CVE ID: | ||
Rule Protection Details |
---|
Description: | pgAdmin versions 8.11 and earlier are vulnerable to a security flaw in OAuth2 authentication. This vulnerability allows an attacker to potentially obtain the client ID and secret, leading to unauthorized access to user data. | |
Impact: | An attacker could exploit this vulnerability to have unspecified effect. | |
Affected OS: | Windows, Linux, Others | |
Reference: | https://github.com/pgadmin-org/pgadmin4/issues/7945 |
|
Solutions |
---|
Please refer to announcements or patches release by the vendor: https://www.pgadmin.org/docs/pgadmin4/8.12/release_notes_8_12.html |