pgAdmin <= 8.4 is affected by a Remote Code Execution (RCE) vulnerability through the validate binary path API. This vulnerability allows attackers to execute arbitrary code on the server hosting PGAdmin, posing a severe risk to the database management system's integrity and the security of the underlying data.
History

Mon, 17 Mar 2025 17:00:00 +0000

Type Values Removed Values Added
First Time appeared Pgadmin pgadmin 4
CPEs cpe:2.3:a:pgadmin:pgadmin:*:*:*:*:*:postgresql:*:* cpe:2.3:a:pgadmin:pgadmin_4:*:*:*:*:*:postgresql:*:*
Vendors & Products Pgadmin pgadmin
Pgadmin pgadmin 4

Fri, 14 Mar 2025 17:15:00 +0000

Type Values Removed Values Added
First Time appeared Postgresql
Postgresql pgadmin 4
Weaknesses CWE-77
CPEs cpe:2.3:a:postgresql:pgadmin_4:*:*:*:*:*:*:*:*
Vendors & Products Postgresql
Postgresql pgadmin 4
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 13 Feb 2025 18:00:00 +0000

Type Values Removed Values Added
Description pgAdmin <= 8.4 is affected by a Remote Code Execution (RCE) vulnerability through the validate binary path API. This vulnerability allows attackers to execute arbitrary code on the server hosting PGAdmin, posing a severe risk to the database management system's integrity and the security of the underlying data. pgAdmin <= 8.4 is affected by a Remote Code Execution (RCE) vulnerability through the validate binary path API. This vulnerability allows attackers to execute arbitrary code on the server hosting PGAdmin, posing a severe risk to the database management system's integrity and the security of the underlying data.

Tue, 11 Feb 2025 16:45:00 +0000

Type Values Removed Values Added
First Time appeared Fedoraproject
Fedoraproject fedora
Pgadmin
Pgadmin pgadmin
Weaknesses NVD-CWE-noinfo
CPEs cpe:2.3:a:pgadmin:pgadmin:*:*:*:*:*:postgresql:*:*
cpe:2.3:o:fedoraproject:fedora:39:*:*:*:*:*:*:*
Vendors & Products Fedoraproject
Fedoraproject fedora
Pgadmin
Pgadmin pgadmin

Wed, 21 Aug 2024 23:30:00 +0000


cve-icon MITRE

Status: PUBLISHED

Assigner: PostgreSQL

Published: 2024-04-04T14:59:37.280Z

Updated: 2025-03-14T16:35:25.051Z

Reserved: 2024-03-30T03:46:32.060Z

Link: CVE-2024-3116

cve-icon Vulnrichment

Updated: 2024-08-19T07:47:48.299Z

cve-icon NVD

Status : Modified

Published: 2024-04-04T15:15:39.667

Modified: 2025-03-17T16:43:52.873

Link: CVE-2024-3116

cve-icon Redhat

No data.