pgAdmin <= 8.4 is affected by a Remote Code Execution (RCE) vulnerability through the validate binary path API. This vulnerability allows attackers to execute arbitrary code on the server hosting PGAdmin, posing a severe risk to the database management system's integrity and the security of the underlying data.
Metrics
Affected Vendors & Products
References
History
Mon, 17 Mar 2025 17:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Pgadmin pgadmin 4
|
|
CPEs | cpe:2.3:a:pgadmin:pgadmin_4:*:*:*:*:*:postgresql:*:* | |
Vendors & Products |
Pgadmin pgadmin
|
Pgadmin pgadmin 4
|
Fri, 14 Mar 2025 17:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Postgresql
Postgresql pgadmin 4 |
|
Weaknesses | CWE-77 | |
CPEs | cpe:2.3:a:postgresql:pgadmin_4:*:*:*:*:*:*:*:* | |
Vendors & Products |
Postgresql
Postgresql pgadmin 4 |
|
Metrics |
ssvc
|
Thu, 13 Feb 2025 18:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | pgAdmin <= 8.4 is affected by a Remote Code Execution (RCE) vulnerability through the validate binary path API. This vulnerability allows attackers to execute arbitrary code on the server hosting PGAdmin, posing a severe risk to the database management system's integrity and the security of the underlying data. | pgAdmin <= 8.4 is affected by a Remote Code Execution (RCE) vulnerability through the validate binary path API. This vulnerability allows attackers to execute arbitrary code on the server hosting PGAdmin, posing a severe risk to the database management system's integrity and the security of the underlying data. |
Tue, 11 Feb 2025 16:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Fedoraproject
Fedoraproject fedora Pgadmin Pgadmin pgadmin |
|
Weaknesses | NVD-CWE-noinfo | |
CPEs | cpe:2.3:a:pgadmin:pgadmin:*:*:*:*:*:postgresql:*:* cpe:2.3:o:fedoraproject:fedora:39:*:*:*:*:*:*:* |
|
Vendors & Products |
Fedoraproject
Fedoraproject fedora Pgadmin Pgadmin pgadmin |
Wed, 21 Aug 2024 23:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
References |
|

Status: PUBLISHED
Assigner: PostgreSQL
Published: 2024-04-04T14:59:37.280Z
Updated: 2025-03-14T16:35:25.051Z
Reserved: 2024-03-30T03:46:32.060Z
Link: CVE-2024-3116

Updated: 2024-08-19T07:47:48.299Z

Status : Modified
Published: 2024-04-04T15:15:39.667
Modified: 2025-03-17T16:43:52.873
Link: CVE-2024-3116

No data.