Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2025-2291

Опубликовано: 16 апр. 2025
Источник: debian
EPSS Низкий

Описание

Password can be used past expiry in PgBouncer due to auth_query not taking into account Postgres its VALID UNTIL value, which allows an attacker to log in with an already expired password

Пакеты

ПакетСтатусВерсия исправленияРелизТип
pgbouncerfixed1.24.1-1package
pgbouncerno-dsabookwormpackage

Примечания

  • Fixed by: https://github.com/pgbouncer/pgbouncer/commit/9912ee7f1af2e1b81d4d624a0da1cb49075ee78a (pgbouncer_1_24_1)

EPSS

Процентиль: 6%
0.00027
Низкий

Связанные уязвимости

CVSS3: 8.1
ubuntu
4 месяца назад

Password can be used past expiry in PgBouncer due to auth_query not taking into account Postgres its VALID UNTIL value, which allows an attacker to log in with an already expired password

CVSS3: 8.1
nvd
4 месяца назад

Password can be used past expiry in PgBouncer due to auth_query not taking into account Postgres its VALID UNTIL value, which allows an attacker to log in with an already expired password

CVSS3: 8.1
msrc
4 месяца назад

Описание отсутствует

CVSS3: 8.1
redos
2 месяца назад

Уязвимость pgbouncer

CVSS3: 8.1
github
4 месяца назад

Password can be used past expiry in PgBouncer due to auth_query not taking into account Postgres its VALID UNTIL value, which allows an attacker to log in with an already expired password

EPSS

Процентиль: 6%
0.00027
Низкий