Back to overview

CVE-2024-2044

CRITICAL Exploitation: PoC
9.9
CVSS 3.1
Description
pgAdmin <= 8.3 is affected by a path-traversal vulnerability while deserializing users’ sessions in the session handling code. If the server is running on Windows, an unauthenticated attacker can load and deserialize remote pickle objects and gain code execution. If the server is running on POSIX/Linux, an authenticated attacker can upload pickle objects, deserialize them, and gain code execution.

Metadata

CVE ID
CVE-2024-2044
State
PUBLISHED
Assigner
PostgreSQL
Reserved
2024-02-29 23:14 UTC
Published
2024-03-07 20:48 UTC
Last updated
2025-02-13 17:32 UTC
Primary CWE
CWE-31
CWE-31 Path Traversal: 'dir\..\..\filename'
Vendor / Product
pgadmin.org / pgAdmin 4
Sources
cve.org  ·  NVD

Severity & Metrics

9.9 CRITICAL CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
SSVC — CISA Coordinator
Exploitation
PoC
Automatable
no
Tech. Impact
total
Affected products (1)
VendorProductPlatformVersions
pgadmin.org pgAdmin 4 0 < 8.4
Weakness (CWE)
CWESourceDescription
CWE-31 adp CWE-31 Path Traversal: 'dir\..\..\filename'
CVSS scores (1)
ScoreSeverityVersionSourceVector
9.9 CRITICAL 3.1 cna CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Back to overview