Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-72rj-36qc-47g7

Опубликовано: 27 апр. 2021
Источник: github
Github: Прошло ревью
CVSS3: 7.5

Описание

Pgsync Contains Cleartext Transmission of Sensitive Information

pgsync before 0.6.7 is affected by Information Disclosure of sensitive information. Syncing the schema with the --schema-first and --schema-only options is mishandled. For example, the sslmode connection parameter may be lost, which means that SSL would not be used.

Пакеты

Наименование

pgsync

rubygems
Затронутые версииВерсия исправления

< 0.6.7

0.6.7

EPSS

Процентиль: 40%
0.00182
Низкий

7.5 High

CVSS3

Дефекты

CWE-319

Связанные уязвимости

CVSS3: 7.5
nvd
почти 5 лет назад

pgsync before 0.6.7 is affected by Information Disclosure of sensitive information. Syncing the schema with the --schema-first and --schema-only options is mishandled. For example, the sslmode connection parameter may be lost, which means that SSL would not be used.

EPSS

Процентиль: 40%
0.00182
Низкий

7.5 High

CVSS3

Дефекты

CWE-319