PgAdmin Product Security Update Advisory (CVE-2024-3116)

Overview

 

PgAdmin has released a security update to address a vulnerability in its products. users of affected products are advised to update to the latest version.

 

Affected Products

 

pgAdmin 8.4 or below

 

Resolved Vulnerabilities

 

Remote code execution vulnerability via the validate binary path API in pgAdmin (CVE-2024-3116)

 

Vulnerability Patches

 

vulnerability Patches have been made available in the latest update. Please follow the instructions on the Referenced Sites to update to the latest Vulnerability Patches version.

pgAdmin 8.5 version

 

Referenced Sites

 

[1] CVE-2024-3116 Detail

https://nvd.nist.gov/vuln/detail/CVE-2024-3116

[2] Remote Code Execution Vulnerability in PGAdmin #7326

https://github.com/pgadmin-org/pgadmin4/issues/7326