CVE-2024-9014

HIGH8.6EPSS 92.9%

OAuth2 client ID and secret exposed through the web browser

發布日:2024/9/23修改日:2024/10/1

描述

pgAdmin versions 8.11 and earlier are vulnerable to a security flaw in OAuth2 authentication. This vulnerability allows an attacker to potentially obtain the client ID and secret, leading to unauthorized access to user data.

受影響套件(1)

CVSS 分數

來源版本嚴重程度向量
osvCVSS 3.1HIGH8.6CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N

參考連結(4)