Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2025-49146

Опубликовано: 11 июн. 2025
Источник: redhat
CVSS3: 8.2

Описание

pgjdbc is an open source postgresql JDBC Driver. From 42.7.4 and until 42.7.7, when the PostgreSQL JDBC driver is configured with channel binding set to required (default value is prefer), the driver would incorrectly allow connections to proceed with authentication methods that do not support channel binding (such as password, MD5, GSS, or SSPI authentication). This could allow a man-in-the-middle attacker to intercept connections that users believed were protected by channel binding requirements. This vulnerability is fixed in 42.7.7.

A connection handling flaw was found in the pgjdbc connection driver in configurations that require channel binding. Connections created with authentication methods that should not allow channel binding permit connections to use channel binding. This flaw allows attackers to position themselves in the middle of a connection and intercept the connection.

Меры по смягчению последствий

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Cryostat 4postgresqlAffected
Red Hat AMQ Broker 7postgresqlAffected
Red Hat build of Apache Camel for Spring Boot 4postgresqlAffected
Red Hat build of Apicurio Registry 2postgresqlAffected
Red Hat build of Apicurio Registry 3postgresqlAffected
Red Hat build of Debezium 2postgresqlNot affected
Red Hat build of Debezium 3postgresqlNot affected
Red Hat build of OptaPlanner 8postgresqlNot affected
Red Hat build of Quarkusquarkus-bomNot affected
Red Hat Data Grid 8postgresqlNot affected

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-287
https://bugzilla.redhat.com/show_bug.cgi?id=2372307pgjdbc: pgjdbc insecure authentication in channel binding

8.2 High

CVSS3

Связанные уязвимости

CVSS3: 8.2
ubuntu
7 дней назад

pgjdbc is an open source postgresql JDBC Driver. From 42.7.4 and until 42.7.7, when the PostgreSQL JDBC driver is configured with channel binding set to required (default value is prefer), the driver would incorrectly allow connections to proceed with authentication methods that do not support channel binding (such as password, MD5, GSS, or SSPI authentication). This could allow a man-in-the-middle attacker to intercept connections that users believed were protected by channel binding requirements. This vulnerability is fixed in 42.7.7.

CVSS3: 8.2
nvd
7 дней назад

pgjdbc is an open source postgresql JDBC Driver. From 42.7.4 and until 42.7.7, when the PostgreSQL JDBC driver is configured with channel binding set to required (default value is prefer), the driver would incorrectly allow connections to proceed with authentication methods that do not support channel binding (such as password, MD5, GSS, or SSPI authentication). This could allow a man-in-the-middle attacker to intercept connections that users believed were protected by channel binding requirements. This vulnerability is fixed in 42.7.7.

CVSS3: 8.2
debian
7 дней назад

pgjdbc is an open source postgresql JDBC Driver. From 42.7.4 and until ...

CVSS3: 8.2
github
7 дней назад

pgjdbc Client Allows Fallback to Insecure Authentication Despite channelBinding=require Configuration

CVSS3: 8.2
fstec
8 дней назад

Уязвимость драйвера JDBC pgjdbc для подключения Java-программ к базе данных PostgreSQL, позволяющая нарушителю реализовать атаку типа «человек посередине»

8.2 High

CVSS3