Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2018-10936

Опубликовано: 27 авг. 2018
Источник: redhat
CVSS3: 8.1
EPSS Низкий

Описание

A weakness was found in postgresql-jdbc before version 42.2.5. It was possible to provide an SSL Factory and not check the host name if a host name verifier was not provided to the driver. This could lead to a condition where a man-in-the-middle attacker could masquerade as a trusted server by providing a certificate for the wrong host, as long as it was signed by a trusted CA.

A weakness was found in postgresql-jdbc. It was possible to provide an SSL Factory and not check the host name if a host name verifier was not provided to the driver. This could lead to a condition where a man-in-the-middle attacker could masquerade as a trusted server by providing a certificate for the wrong host, as long as it was signed by a trusted CA.

Меры по смягчению последствий

Applications using postgresql-jdbc should have their SSL configuration reviewed to ensure that host name verification is not disabled and only trusted CAs are accepted. This vulnerability only impacts usage of postgresql-jdbc with a non-default SSL Factory, provided by the sslfactory parameter. If this parameter is not given, the default LibPQFactory is used, which is not vulnerable.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
CloudForms Management Engine 5postgresql94Not affected
Red Hat Ansible Tower 3postgresql96Not affected
Red Hat Enterprise Linux 6postgresql-jdbcWill not fix
Red Hat Enterprise Linux 7postgresql-jdbcFix deferred
Red Hat Enterprise Linux 8postgresql-jdbcFix deferred
Red Hat Mobile Application Platform 4millicoreNot affected
Red Hat Virtualization 4postgresql-jdbcWill not fix

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-297
https://bugzilla.redhat.com/show_bug.cgi?id=1622225PostgreSQL: Postgres JDBC driver does not perform host name validation by default

EPSS

Процентиль: 75%
0.00892
Низкий

8.1 High

CVSS3

Связанные уязвимости

CVSS3: 8.1
ubuntu
больше 7 лет назад

A weakness was found in postgresql-jdbc before version 42.2.5. It was possible to provide an SSL Factory and not check the host name if a host name verifier was not provided to the driver. This could lead to a condition where a man-in-the-middle attacker could masquerade as a trusted server by providing a certificate for the wrong host, as long as it was signed by a trusted CA.

CVSS3: 8.1
nvd
больше 7 лет назад

A weakness was found in postgresql-jdbc before version 42.2.5. It was possible to provide an SSL Factory and not check the host name if a host name verifier was not provided to the driver. This could lead to a condition where a man-in-the-middle attacker could masquerade as a trusted server by providing a certificate for the wrong host, as long as it was signed by a trusted CA.

CVSS3: 8.1
debian
больше 7 лет назад

A weakness was found in postgresql-jdbc before version 42.2.5. It was ...

github
больше 7 лет назад

Moderate severity vulnerability that affects org.postgresql:pgjdbc-aggregate

EPSS

Процентиль: 75%
0.00892
Низкий

8.1 High

CVSS3