OAuth2 client ID and secret exposed through the web browser
pgAdmin versions 8.11 and earlier are vulnerable to a security flaw in OAuth2 authentication. This vulnerability allows an attacker to potentially obtain the client ID and secret, leading to unauthorized access to user data.
02 / AFFECTED SOFTWARE
Affected packages
59 explicit affected versions
59 explicit affected versions
105 explicit affected versions
03 / CONNECTIONS
Connected vulnerabilities
04 / EVIDENCE
Source records
pgAdmin versions 8.11 and earlier are vulnerable to a security flaw in OAuth2 authentication. This vulnerability allows an attacker to potentially obtain the client ID and secret, leading to unauthorized access to user data.
pgAdmin versions 8.11 and earlier are vulnerable to a security flaw in OAuth2 authentication. This vulnerability allows an attacker to potentially obtain the client ID and secret, leading to unauthorized access to user data.
pgAdmin versions 8.11 and earlier are vulnerable to a security flaw in OAuth2 authentication. This vulnerability allows an attacker to potentially obtain the client ID and secret, leading to unauthorized access to user data.
05 / REFERENCES
Further evidence
- https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/9xxx/CVE-2024-9014.json
- https://github.com/pgadmin-org/pgadmin4
- https://github.com/pgadmin-org/pgadmin4/issues/7945
- https://nvd.nist.gov/vuln/detail/CVE-2024-9014
- https://www.pgadmin.org/docs/pgadmin4/8.12/release_notes_8_12.html
- https://github.com/advisories/GHSA-jm9x-rx9x-wpqj
- https://pypi.org/project/pgadmin4