Описание
Untrusted search path in auth_query connection handler in PgBouncer before 1.25.1 allows an unauthenticated attacker to execute arbitrary SQL during authentication via a malicious search_path parameter in the StartupMessage.
Уязвимые конфигурации
EPSS
7.5 High
CVSS3
8.1 High
CVSS3
Дефекты
Связанные уязвимости
Untrusted search path in auth_query connection handler in PgBouncer before 1.25.1 allows an unauthenticated attacker to execute arbitrary SQL during authentication via a malicious search_path parameter in the StartupMessage.
Untrusted search path in auth_query connection in PgBouncer
Untrusted search path in auth_query connection handler in PgBouncer be ...
Untrusted search path in auth_query connection handler in PgBouncer before 1.25.0 allows an unauthenticated attacker to execute arbitrary SQL during authentication via a malicious search_path parameter in the StartupMessage.
Уязвимость программного обеспечения для пула соединения в PostgreSQL PgBouncer, связанная с ненадежным путем поиска, позволяющая нарушителю вызвать отказ в обслуживании
EPSS
7.5 High
CVSS3
8.1 High
CVSS3