9.9
CRITICAL
CVE-2024-9014
pgAdmin OAuth2 Authentication Bypass
Description

pgAdmin versions 8.11 and earlier are vulnerable to a security flaw in OAuth2 authentication. This vulnerability allows an attacker to potentially obtain the client ID and secret, leading to unauthorized access to user data.

INFO

Published Date :

Sept. 23, 2024, 5:15 p.m.

Last Modified :

Sept. 26, 2024, 1:32 p.m.

Source :

f86ef6dc-4d3a-42ad-8f28-e6d5547a5007

Remotely Exploitable :

Yes !

Impact Score :

6.0

Exploitability Score :

3.1
Public PoC/Exploit Available at Github

CVE-2024-9014 has a 6 public PoC/Exploit available at Github. Go to the Public Exploits tab to see the list.

Affected Products

The following products are affected by CVE-2024-9014 vulnerability. Even if cvefeed.io is aware of the exact versions of the products that are affected, the information is not represented in the table below.

ID Vendor Product Action
1 Pgadmin pgadmin
References to Advisories, Solutions, and Tools

Here, you will find a curated list of external links that provide in-depth information, practical solutions, and valuable tools related to CVE-2024-9014.

URL Resource
https://github.com/pgadmin-org/pgadmin4/issues/7945

We scan GitHub repositories to detect new proof-of-concept exploits. Following list is a collection of public exploits and proof-of-concepts, which have been published on GitHub (sorted by the most recently updated).

搭建漏洞

HTML

Updated: 1 month ago
0 stars 0 fork 0 watcher
Born at : Nov. 20, 2024, 7:53 a.m. This repo has been linked 32 different CVEs too.

Proof-of-Concept for CVE-2024-9014

Updated: 2 months, 1 week ago
7 stars 1 fork 1 watcher
Born at : Sept. 26, 2024, 10:34 a.m. This repo has been linked 1 different CVEs too.

漏洞文库 wiki.wy876.cn

poc

HTML

Updated: 2 weeks, 4 days ago
437 stars 86 fork 86 watcher
Born at : Dec. 31, 2023, 7:18 a.m. This repo has been linked 33 different CVEs too.

收集整理漏洞EXP/POC,大部分漏洞来源网络,目前收集整理了1300多个poc/exp,长期更新。

poc

Updated: 3 weeks ago
4250 stars 867 fork 867 watcher
Born at : Aug. 19, 2023, 12:08 p.m. This repo has been linked 159 different CVEs too.

一个CVE漏洞预警知识库 no exp/poc

Updated: 1 month, 1 week ago
95 stars 11 fork 11 watcher
Born at : Jan. 5, 2023, 2:19 a.m. This repo has been linked 133 different CVEs too.

📡 PoC auto collect from GitHub. ⚠️ Be careful Malware.

security cve exploit poc vulnerability

Updated: 2 weeks, 2 days ago
6566 stars 1140 fork 1140 watcher
Born at : Dec. 8, 2019, 1:03 p.m. This repo has been linked 958 different CVEs too.

Results are limited to the first 15 repositories due to potential performance issues.

The following list is the news that have been mention CVE-2024-9014 vulnerability anywhere in the article.

  • Cybersecurity News
Active Exploits Target Cisco ASA and FTD VPNs: Urgent Update Needed (CVE-2024-20481)

Cisco has disclosed an actively exploited vulnerability (CVE-2024-20481) in its Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD) software that could allow attackers to launch denia ... Read more

Published Date: Oct 24, 2024 (1 month, 4 weeks ago)
  • Cybersecurity News
Cryptojacking Alert: Hackers Exploit gRPC and HTTP/2 to Deploy Miners

Attack chain | Image: Trend MicroTrend Micro researchers have uncovered a new and unconventional method used by cybercriminals to deploy the SRBMiner cryptominer on Docker remote API servers. This att ... Read more

Published Date: Oct 23, 2024 (2 months ago)
  • Cybersecurity News
F5 BIG-IP Vulnerability (CVE-2024-45844): Access Control Bypass Risk, PoC Available

A critical vulnerability has been identified in F5 BIG-IP, a popular network traffic management and security solution. The vulnerability, tracked as CVE-2024-45844 and assigned a CVSSv4 score of 8.6 ( ... Read more

Published Date: Oct 18, 2024 (2 months ago)
  • Cybersecurity News
D3D Security IP Cameras Risk Data Breach, Live Feed Access, No Patch Available

The Indian Computer Emergency Response Team (CERT-In) has issued an urgent advisory concerning two critical vulnerabilities discovered in the D3D Security IP Camera D8801, which could potentially allo ... Read more

Published Date: Oct 05, 2024 (2 months, 2 weeks ago)
  • Cybersecurity News
Critical Vulnerabilities in Kia’s Dealer Portal Expose Millions of Vehicles to Remote Hijacking

Image: SamcurryIn a startling revelation that underscores the growing cybersecurity risks in the automotive industry, security researchers have uncovered critical vulnerabilities in Kia’s dealer porta ... Read more

Published Date: Sep 27, 2024 (2 months, 3 weeks ago)
  • Cybersecurity News
FlashArray, FlashBlade at Risk: Pure Storage Reveals CVSS 10 Vulnerabilities

Pure Storage has released a critical security advisory detailing multiple high-severity vulnerabilities impacting its FlashArray and FlashBlade storage systems. These vulnerabilities, some with a maxi ... Read more

Published Date: Sep 26, 2024 (2 months, 3 weeks ago)
  • Cybersecurity News
CVE-2024-9014 (CVSS 9.9): pgAdmin’s Critical Vulnerability Puts User Data at Risk

pgAdmin, the leading open-source management tool for PostgreSQL databases, has released an urgent security update to address a critical vulnerability affecting versions 8.11 and earlier. This flaw, id ... Read more

Published Date: Sep 25, 2024 (2 months, 4 weeks ago)

The following table lists the changes that have been made to the CVE-2024-9014 vulnerability over time.

Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability's severity, exploitability, or other characteristics.

  • CVE Modified by 134c704f-9b21-4f2e-91b3-4a467353bcc0

    Sep. 23, 2024

    Action Type Old Value New Value
    Added CWE CISA-ADP CWE-522
  • CVE Received by f86ef6dc-4d3a-42ad-8f28-e6d5547a5007

    Sep. 23, 2024

    Action Type Old Value New Value
    Added Description pgAdmin versions 8.11 and earlier are vulnerable to a security flaw in OAuth2 authentication. This vulnerability allows an attacker to potentially obtain the client ID and secret, leading to unauthorized access to user data.
    Added Reference PostgreSQL https://github.com/pgadmin-org/pgadmin4/issues/7945 [No types assigned]
    Added CVSS V3.1 PostgreSQL AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
EPSS is a daily estimate of the probability of exploitation activity being observed over the next 30 days. Following chart shows the EPSS score history of the vulnerability.
CWE - Common Weakness Enumeration

While CVE identifies specific instances of vulnerabilities, CWE categorizes the common flaws or weaknesses that can lead to vulnerabilities. CVE-2024-9014 is associated with the following CWEs:

CVSS31 - Vulnerability Scoring System
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability