← Back

CVE-2024-4215

nvd nist
Published: May 2, 2024Modified: Jun 17, 2026

JSON object

Loading...
8.8
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Exploitability: 2.8 / Impact: 5.9
Source: NVD

Description

pgAdmin <= 8.5 is affected by a multi-factor authentication bypass vulnerability. This vulnerability allows an attacker with knowledge of a legitimate account’s username and password may authenticate to the application and perform sensitive actions within the application, such as managing files and executing SQL queries, regardless of the account’s MFA enrollment status.

Affected (2)

1 product
Fedora
1 product
Pgadmin 4
Configuration A
2 vulnerable
Vulnerable SoftwareAffected Versions
Version 40
Before 8.6

References (4)

Timeline

No history available yet.