Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

CVE ID:CVE-2024-2044
Description:pgAdmin <= 8.3 is affected by a path-traversal vulnerability while deserializing users’ sessions in the session handling code. If the server is running on Windows, an unauthenticated attacker can load and deserialize remote pickle objects and gain code execution. If the server is running on POSIX/Linux, an authenticated attacker can upload pickle objects, deserialize them, and gain code execution.
Test IDs: 1.3.6.1.4.1.25623.1.0.886258   1.3.6.1.4.1.25623.1.1.4.2024.1340.1   1.3.6.1.4.1.25623.1.0.856092   1.3.6.1.4.1.25623.1.0.886241  
Cross References: Common Vulnerability Exposure (CVE) ID: CVE-2024-2044
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/LUYN2JXKKHFSVTASH344TBRGWDH64XQV/
https://github.com/pgadmin-org/pgadmin4/issues/7258
https://github.com/pgadmin-org/pgadmin4/issues/7258
https://www.shielder.com/advisories/pgadmin-path-traversal_leads_to_unsafe_deserialization_and_rce/
https://www.shielder.com/advisories/pgadmin-path-traversal_leads_to_unsafe_deserialization_and_rce/




© 1998-2025 E-Soft Inc. All rights reserved.