Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-qj9w-64mv-p2fw

Опубликовано: 16 апр. 2025
Источник: github
Github: Не прошло ревью
CVSS3: 8.1

Описание

Password can be used past expiry in PgBouncer due to auth_query not taking into account Postgres its VALID UNTIL value, which allows an attacker to log in with an already expired password

Password can be used past expiry in PgBouncer due to auth_query not taking into account Postgres its VALID UNTIL value, which allows an attacker to log in with an already expired password

EPSS

Процентиль: 27%
0.00347
Низкий

8.1 High

CVSS3

Дефекты

CWE-324

Связанные уязвимости

CVSS3: 8.1
ubuntu
больше 1 года назад

Password can be used past expiry in PgBouncer due to auth_query not taking into account Postgres its VALID UNTIL value, which allows an attacker to log in with an already expired password

CVSS3: 8.1
nvd
больше 1 года назад

Password can be used past expiry in PgBouncer due to auth_query not taking into account Postgres its VALID UNTIL value, which allows an attacker to log in with an already expired password

CVSS3: 8.1
msrc
5 месяцев назад

PgBouncer default auth_query does not take Postgres password expiry into account

CVSS3: 8.1
debian
больше 1 года назад

Password can be used past expiry in PgBouncer due to auth_query not ta ...

CVSS3: 8.1
fstec
больше 1 года назад

Уязвимость программы для пула соединения в PostgreSQL PgBouncer, связанная с недостатками процедуры аутентификации, позволяющая нарушителю получить несанкционированный доступ к приложению

EPSS

Процентиль: 27%
0.00347
Низкий

8.1 High

CVSS3

Дефекты

CWE-324