Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2026-14672

Опубликовано: 13 авг. 2026
Источник: ubuntu
Приоритет: medium
CVSS3: 5.3

Описание

Observable response discrepancy in PostgreSQL SCRAM authentication allows an unauthenticated user to test the existence of a user via observing the SCRAM iteration count. This requires the probed user to have a non-default scram_iterations count, because the authentication challenge for a nonexistent user reports the default scram_iterations. Within major versions 16-18, minor versions before PostgreSQL 18.5, 17.11, and 16.15 are affected. Versions before PostgreSQL 16 are unaffected.

РелизСтатусПримечание
devel

DNE

esm-infra/bionic

not-affected

16+ only
jammy

DNE

noble

DNE

resolute

DNE

upstream

ignored

end of life

Показывать по

РелизСтатусПримечание
devel

DNE

esm-infra/focal

not-affected

16+ only
jammy

DNE

noble

DNE

resolute

DNE

upstream

ignored

end of life

Показывать по

РелизСтатусПримечание
devel

DNE

jammy

not-affected

16+ only
noble

DNE

resolute

DNE

upstream

not-affected

16+ only

Показывать по

РелизСтатусПримечание
devel

DNE

jammy

DNE

noble

released

16.15-0ubuntu0.24.04.1
resolute

DNE

upstream

needs-triage

Показывать по

РелизСтатусПримечание
devel

pending

18.6-3
jammy

DNE

noble

DNE

resolute

released

18.6-0ubuntu0.26.04.1
upstream

needs-triage

Показывать по

РелизСтатусПримечание
devel

DNE

esm-infra-legacy/trusty

deferred

2019-08-23
jammy

DNE

noble

DNE

resolute

DNE

upstream

ignored

end of life

Показывать по

РелизСтатусПримечание
devel

DNE

esm-infra-legacy/xenial

not-affected

16+ only
jammy

DNE

noble

DNE

resolute

DNE

upstream

ignored

end of life

Показывать по

5.3 Medium

CVSS3

Связанные уязвимости

CVSS3: 5.3
nvd
10 дней назад

Observable response discrepancy in PostgreSQL SCRAM authentication allows an unauthenticated user to test the existence of a user via observing the SCRAM iteration count. This requires the probed user to have a non-default scram_iterations count, because the authentication challenge for a nonexistent user reports the default scram_iterations. Within major versions 16-18, minor versions before PostgreSQL 18.5, 17.11, and 16.15 are affected. Versions before PostgreSQL 16 are unaffected.

msrc
9 дней назад

PostgreSQL observable response discrepancy with non-default scram_iterations provides user existence oracle

CVSS3: 5.3
debian
10 дней назад

Observable response discrepancy in PostgreSQL SCRAM authentication all ...

CVSS3: 5.3
github
10 дней назад

Observable response discrepancy in PostgreSQL SCRAM authentication allows an unauthenticated user to test the existence of a user via observing the SCRAM iteration count. This requires the probed user to have a non-default scram_iterations count, because the authentication challenge for a nonexistent user reports the default scram_iterations. Within major versions 16-18, minor versions before PostgreSQL 18.5, 17.11, and 16.15 are affected. Versions before PostgreSQL 16 are unaffected.

CVSS3: 5.3
fstec
11 дней назад

Уязвимость подсистемы аутентификации SCRAM системы управления базами данных PostgreSQL, позволяющая нарушителю раскрыть защищаемую информацию

5.3 Medium

CVSS3