Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2025-2291

Опубликовано: 16 апр. 2025
Источник: debian

Описание

Password can be used past expiry in PgBouncer due to auth_query not taking into account Postgres its VALID UNTIL value, which allows an attacker to log in with an already expired password

Пакеты

ПакетСтатусВерсия исправленияРелизТип
pgbouncerfixed1.24.1-1package
pgbouncerfixed1.18.0-1+deb12u1bookwormpackage

Примечания

  • Fixed by: https://github.com/pgbouncer/pgbouncer/commit/9912ee7f1af2e1b81d4d624a0da1cb49075ee78a (pgbouncer_1_24_1)

Связанные уязвимости

CVSS3: 8.1
ubuntu
больше 1 года назад

Password can be used past expiry in PgBouncer due to auth_query not taking into account Postgres its VALID UNTIL value, which allows an attacker to log in with an already expired password

CVSS3: 8.1
nvd
больше 1 года назад

Password can be used past expiry in PgBouncer due to auth_query not taking into account Postgres its VALID UNTIL value, which allows an attacker to log in with an already expired password

CVSS3: 8.1
msrc
5 месяцев назад

PgBouncer default auth_query does not take Postgres password expiry into account

CVSS3: 8.1
github
больше 1 года назад

Password can be used past expiry in PgBouncer due to auth_query not taking into account Postgres its VALID UNTIL value, which allows an attacker to log in with an already expired password

CVSS3: 8.1
fstec
больше 1 года назад

Уязвимость программы для пула соединения в PostgreSQL PgBouncer, связанная с недостатками процедуры аутентификации, позволяющая нарушителю получить несанкционированный доступ к приложению