pgAdmin <= 8.4 is affected by a Remote Code Execution (RCE) vulnerability through the validate binary path API. This vulnerability allows attackers to execute arbitrary code on the server hosting PGAdmin, posing a severe risk to the database management system's integrity and the security of the underlying data.
Metrics
Affected Vendors & Products
References
History
Mon, 17 Mar 2025 17:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Pgadmin pgadmin 4
|
|
| CPEs | cpe:2.3:a:pgadmin:pgadmin_4:*:*:*:*:*:postgresql:*:* | |
| Vendors & Products |
Pgadmin pgadmin
|
Pgadmin pgadmin 4
|
Fri, 14 Mar 2025 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Postgresql
Postgresql pgadmin 4 |
|
| Weaknesses | CWE-77 | |
| CPEs | cpe:2.3:a:postgresql:pgadmin_4:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Postgresql
Postgresql pgadmin 4 |
|
| Metrics |
ssvc
|
Thu, 13 Feb 2025 18:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | pgAdmin <= 8.4 is affected by a Remote Code Execution (RCE) vulnerability through the validate binary path API. This vulnerability allows attackers to execute arbitrary code on the server hosting PGAdmin, posing a severe risk to the database management system's integrity and the security of the underlying data. | pgAdmin <= 8.4 is affected by a Remote Code Execution (RCE) vulnerability through the validate binary path API. This vulnerability allows attackers to execute arbitrary code on the server hosting PGAdmin, posing a severe risk to the database management system's integrity and the security of the underlying data. |
Tue, 11 Feb 2025 16:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Fedoraproject
Fedoraproject fedora Pgadmin Pgadmin pgadmin |
|
| Weaknesses | NVD-CWE-noinfo | |
| CPEs | cpe:2.3:a:pgadmin:pgadmin:*:*:*:*:*:postgresql:*:* cpe:2.3:o:fedoraproject:fedora:39:*:*:*:*:*:*:* |
|
| Vendors & Products |
Fedoraproject
Fedoraproject fedora Pgadmin Pgadmin pgadmin |
Wed, 21 Aug 2024 23:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Status: PUBLISHED
Assigner: PostgreSQL
Published: 2024-04-04T14:59:37.280Z
Updated: 2025-03-14T16:35:25.051Z
Reserved: 2024-03-30T03:46:32.060Z
Link: CVE-2024-3116
Updated: 2024-08-19T07:47:48.299Z
Status : Modified
Published: 2024-04-04T15:15:39.667
Modified: 2025-03-17T16:43:52.873
Link: CVE-2024-3116
No data.