CVE-2024-3116 is a critical Remote Code Execution (RCE) vulnerability affecting pgAdmin versions 8.4 and earlier, including various Fedora distributions. This flaw allows unauthenticated attackers to execute arbitrary code on the server hosting pgAdmin via the validate binary path API. With a CVSS score of 9.8 (Critical) and an EPSS score indicating high exploitability, this vulnerability poses a severe risk of complete compromise of the database management system and underlying data. While not yet observed in active exploitation, a Metasploit module is publicly available, and its high FAUCET Risk Score of 99/100 underscores its immediate threat, despite limited community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 8.4CPE matchmatch criteria | cpe:2.3:a:pgadmin:pgadmin_4:*:*:*:*:*:postgresql:*:* | ||
39CPE matchmatch criteria | cpe:2.3:o:fedoraproject:fedora:39:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:L
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.