Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2025-46801

Опубликовано: 19 мая 2025
Источник: debian

Описание

Pgpool-II provided by PgPool Global Development Group contains an authentication bypass by primary weakness vulnerability. if the vulnerability is exploited, an attacker may be able to log in to the system as an arbitrary user, allowing them to read or tamper with data in the database, and/or disable the database.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
pgpool2fixed4.6.1-1package

Примечания

  • https://www.pgpool.net/mediawiki/index.php/Main_Page#Pgpool-II_4.6.1.2C_4.5.7.2C_4.4.12.2C_4.3.15_and_4.2.22_officially_released_.282025.2F05.2F15.29_2

  • Fixed by: https://git.postgresql.org/gitweb/?p=pgpool2.git;a=commit;h=d8e2ace8737f64eee2bf5ca74f6294835fb75ccb (V4_6_1)

Связанные уязвимости

CVSS3: 9.8
ubuntu
9 месяцев назад

Pgpool-II provided by PgPool Global Development Group contains an authentication bypass by primary weakness vulnerability. if the vulnerability is exploited, an attacker may be able to log in to the system as an arbitrary user, allowing them to read or tamper with data in the database, and/or disable the database.

CVSS3: 9.8
nvd
9 месяцев назад

Pgpool-II provided by PgPool Global Development Group contains an authentication bypass by primary weakness vulnerability. if the vulnerability is exploited, an attacker may be able to log in to the system as an arbitrary user, allowing them to read or tamper with data in the database, and/or disable the database.

CVSS3: 9.8
redos
8 месяцев назад

Уязвимость postgresql16-pgpool-II

CVSS3: 9.8
redos
8 месяцев назад

Уязвимость postgresql15-pgpool-II

CVSS3: 9.8
redos
8 месяцев назад

Уязвимость postgresql14-pgpool-II