Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-gfpv-wrhp-wwh6

Опубликовано: 13 авг. 2026
Источник: github
Github: Не прошло ревью
CVSS3: 4.2

Описание

Improper enforcement of message integrity in PostgreSQL GSSAPI support allows a user to negotiate GSSAPI contrary to pg_hba.conf rules, via initial direct TLS connection. Despite a pg_hba.conf that appears to require GSSAPI, the connection may exchange data over TLS encryption alone. If the TLS settings are more permissive than the GSS settings, the connection may continue with lesser protection. Within major versions 17-18, minor versions before PostgreSQL 18.5 and 17.11 are affected. Versions before PostgreSQL 17 are unaffected.

Improper enforcement of message integrity in PostgreSQL GSSAPI support allows a user to negotiate GSSAPI contrary to pg_hba.conf rules, via initial direct TLS connection. Despite a pg_hba.conf that appears to require GSSAPI, the connection may exchange data over TLS encryption alone. If the TLS settings are more permissive than the GSS settings, the connection may continue with lesser protection. Within major versions 17-18, minor versions before PostgreSQL 18.5 and 17.11 are affected. Versions before PostgreSQL 17 are unaffected.

EPSS

Процентиль: 0%
0.00079
Низкий

4.2 Medium

CVSS3

Дефекты

CWE-924

Связанные уязвимости

CVSS3: 4.2
ubuntu
10 дней назад

Improper enforcement of message integrity in PostgreSQL GSSAPI support allows a user to negotiate GSSAPI contrary to pg_hba.conf rules, via initial direct TLS connection. Despite a pg_hba.conf that appears to require GSSAPI, the connection may exchange data over TLS encryption alone. If the TLS settings are more permissive than the GSS settings, the connection may continue with lesser protection. Within major versions 17-18, minor versions before PostgreSQL 18.5 and 17.11 are affected. Versions before PostgreSQL 17 are unaffected.

CVSS3: 4.2
nvd
10 дней назад

Improper enforcement of message integrity in PostgreSQL GSSAPI support allows a user to negotiate GSSAPI contrary to pg_hba.conf rules, via initial direct TLS connection. Despite a pg_hba.conf that appears to require GSSAPI, the connection may exchange data over TLS encryption alone. If the TLS settings are more permissive than the GSS settings, the connection may continue with lesser protection. Within major versions 17-18, minor versions before PostgreSQL 18.5 and 17.11 are affected. Versions before PostgreSQL 17 are unaffected.

CVSS3: 4.2
debian
10 дней назад

Improper enforcement of message integrity in PostgreSQL GSSAPI support ...

CVSS3: 5
fstec
11 дней назад

Уязвимость компонента GSSAPI системы управления базами данных PostgreSQL, связанная с ошибками смешения типов данных, позволяющая нарушителю проводить атаки типа "человек посередине"

EPSS

Процентиль: 0%
0.00079
Низкий

4.2 Medium

CVSS3

Дефекты

CWE-924