Описание
Untrusted search path in auth_query connection handler in PgBouncer before 1.25.1 allows an unauthenticated attacker to execute arbitrary SQL during authentication via a malicious search_path parameter in the StartupMessage.
Уязвимые конфигурации
EPSS
7.5 High
CVSS3
8.1 High
CVSS3
Дефекты
Связанные уязвимости
Untrusted search path in auth_query connection handler in PgBouncer before 1.25.1 allows an unauthenticated attacker to execute arbitrary SQL during authentication via a malicious search_path parameter in the StartupMessage.
Untrusted search path in auth_query connection in PgBouncer
Untrusted search path in auth_query connection handler in PgBouncer be ...
Untrusted search path in auth_query connection handler in PgBouncer before 1.25.0 allows an unauthenticated attacker to execute arbitrary SQL during authentication via a malicious search_path parameter in the StartupMessage.
EPSS
7.5 High
CVSS3
8.1 High
CVSS3