Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-568q-9fw5-28wf

Опубликовано: 19 окт. 2018
Источник: github
Github: Прошло ревью

Описание

Moderate severity vulnerability that affects org.postgresql:pgjdbc-aggregate

A weakness was found in postgresql-jdbc before version 42.2.5. It was possible to provide an SSL Factory and not check the host name if a host name verifier was not provided to the driver. This could lead to a condition where a man-in-the-middle attacker could masquerade as a trusted server by providing a certificate for the wrong host, as long as it was signed by a trusted CA.

Пакеты

Наименование

org.postgresql:pgjdbc-aggregate

maven
Затронутые версииВерсия исправления

< 42.2.5

42.2.5

EPSS

Процентиль: 75%
0.00892
Низкий

Дефекты

CWE-297

Связанные уязвимости

CVSS3: 8.1
ubuntu
больше 7 лет назад

A weakness was found in postgresql-jdbc before version 42.2.5. It was possible to provide an SSL Factory and not check the host name if a host name verifier was not provided to the driver. This could lead to a condition where a man-in-the-middle attacker could masquerade as a trusted server by providing a certificate for the wrong host, as long as it was signed by a trusted CA.

CVSS3: 8.1
redhat
больше 7 лет назад

A weakness was found in postgresql-jdbc before version 42.2.5. It was possible to provide an SSL Factory and not check the host name if a host name verifier was not provided to the driver. This could lead to a condition where a man-in-the-middle attacker could masquerade as a trusted server by providing a certificate for the wrong host, as long as it was signed by a trusted CA.

CVSS3: 8.1
nvd
больше 7 лет назад

A weakness was found in postgresql-jdbc before version 42.2.5. It was possible to provide an SSL Factory and not check the host name if a host name verifier was not provided to the driver. This could lead to a condition where a man-in-the-middle attacker could masquerade as a trusted server by providing a certificate for the wrong host, as long as it was signed by a trusted CA.

CVSS3: 8.1
debian
больше 7 лет назад

A weakness was found in postgresql-jdbc before version 42.2.5. It was ...

EPSS

Процентиль: 75%
0.00892
Низкий

Дефекты

CWE-297