Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-qj9w-64mv-p2fw

Опубликовано: 16 апр. 2025
Источник: github
Github: Не прошло ревью
CVSS3: 8.1

Описание

Password can be used past expiry in PgBouncer due to auth_query not taking into account Postgres its VALID UNTIL value, which allows an attacker to log in with an already expired password

Password can be used past expiry in PgBouncer due to auth_query not taking into account Postgres its VALID UNTIL value, which allows an attacker to log in with an already expired password

EPSS

Процентиль: 9%
0.00032
Низкий

8.1 High

CVSS3

Дефекты

CWE-324

Связанные уязвимости

CVSS3: 8.1
ubuntu
7 месяцев назад

Password can be used past expiry in PgBouncer due to auth_query not taking into account Postgres its VALID UNTIL value, which allows an attacker to log in with an already expired password

CVSS3: 8.1
nvd
7 месяцев назад

Password can be used past expiry in PgBouncer due to auth_query not taking into account Postgres its VALID UNTIL value, which allows an attacker to log in with an already expired password

CVSS3: 8.1
msrc
7 месяцев назад

Описание отсутствует

CVSS3: 8.1
debian
7 месяцев назад

Password can be used past expiry in PgBouncer due to auth_query not ta ...

CVSS3: 8.1
redos
5 месяцев назад

Уязвимость pgbouncer

EPSS

Процентиль: 9%
0.00032
Низкий

8.1 High

CVSS3

Дефекты

CWE-324