CVE-2024-4215
8.8
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Exploitability: 2.8 / Impact: 5.9
Source: NVD
Description
pgAdmin <= 8.5 is affected by a multi-factor authentication bypass vulnerability. This vulnerability allows an attacker with knowledge of a legitimate account’s username and password may authenticate to the application and perform sensitive actions within the application, such as managing files and executing SQL queries, regardless of the account’s MFA enrollment status.
Affected (2)
Products: Fedoraproject: Fedora · Pgadmin: Pgadmin 4
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Version 40 | |
| Before 8.6 |
References (4)
Source: f86ef6dc-4d3a-42ad-8f28-e6d5547a5007
Issue Tracking
Source: f86ef6dc-4d3a-42ad-8f28-e6d5547a5007
Mailing List
Source: af854a3a-2127-422b-91ae-364da2661108
Issue Tracking
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing List
Timeline
No history available yet.