Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 18

Количество 18

github логотип

GHSA-hp2m-55fj-8mw5

около 1 месяца назад

Observable response discrepancy in PostgreSQL SCRAM authentication allows an unauthenticated user to test the existence of a user via observing the SCRAM iteration count. This requires the probed user to have a non-default scram_iterations count, because the authentication challenge for a nonexistent user reports the default scram_iterations. Within major versions 16-18, minor versions before PostgreSQL 18.5, 17.11, and 16.15 are affected. Versions before PostgreSQL 16 are unaffected.

CVSS3: 5.3
EPSS: Низкий
ubuntu логотип

CVE-2026-14672

около 1 месяца назад

Observable response discrepancy in PostgreSQL SCRAM authentication allows an unauthenticated user to test the existence of a user via observing the SCRAM iteration count. This requires the probed user to have a non-default scram_iterations count, because the authentication challenge for a nonexistent user reports the default scram_iterations. Within major versions 16-18, minor versions before PostgreSQL 18.6, 17.11, and 16.15 are affected. Versions before PostgreSQL 16 are unaffected.

CVSS3: 5.3
EPSS: Низкий
redhat логотип

CVE-2026-14672

около 1 месяца назад

Observable response discrepancy in PostgreSQL SCRAM authentication allows an unauthenticated user to test the existence of a user via observing the SCRAM iteration count. This requires the probed user to have a non-default scram_iterations count, because the authentication challenge for a nonexistent user reports the default scram_iterations. Within major versions 16-18, minor versions before PostgreSQL 18.5, 17.11, and 16.15 are affected. Versions before PostgreSQL 16 are unaffected.

CVSS3: 5.3
EPSS: Низкий
nvd логотип

CVE-2026-14672

около 1 месяца назад

Observable response discrepancy in PostgreSQL SCRAM authentication allows an unauthenticated user to test the existence of a user via observing the SCRAM iteration count. This requires the probed user to have a non-default scram_iterations count, because the authentication challenge for a nonexistent user reports the default scram_iterations. Within major versions 16-18, minor versions before PostgreSQL 18.6, 17.11, and 16.15 are affected. Versions before PostgreSQL 16 are unaffected.

CVSS3: 5.3
EPSS: Низкий
msrc логотип

CVE-2026-14672

29 дней назад

PostgreSQL observable response discrepancy with non-default scram_iterations provides user existence oracle

CVSS3: 5.3
EPSS: Низкий
debian логотип

CVE-2026-14672

около 1 месяца назад

Observable response discrepancy in PostgreSQL SCRAM authentication all ...

CVSS3: 5.3
EPSS: Низкий
fstec логотип

BDU:2026-11958

около 1 месяца назад

Уязвимость подсистемы аутентификации SCRAM системы управления базами данных PostgreSQL, позволяющая нарушителю раскрыть защищаемую информацию

CVSS3: 5.3
EPSS: Низкий
suse-cvrf логотип

openSUSE-SU-2026:21702-1

22 дня назад

Security update for postgresql17

EPSS: Низкий
suse-cvrf логотип

openSUSE-SU-2026:21701-1

22 дня назад

Security update for postgresql16

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2026:4016-1

15 дней назад

Security update for postgresql17

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2026:4013-1

15 дней назад

Security update for postgresql17

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2026:3963-1

19 дней назад

Security update for postgresql16

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2026:3943-1

19 дней назад

Security update for postgresql16

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2026:3794-1

28 дней назад

Security update for postgresql16

EPSS: Низкий
suse-cvrf логотип

openSUSE-SU-2026:21703-1

22 дня назад

Security update for postgresql18

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2026:4015-1

15 дней назад

Security update for postgresql18

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2026:4014-1

15 дней назад

Security update for postgresql18

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2026:3942-1

19 дней назад

Security update for postgresql18

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-hp2m-55fj-8mw5

Observable response discrepancy in PostgreSQL SCRAM authentication allows an unauthenticated user to test the existence of a user via observing the SCRAM iteration count. This requires the probed user to have a non-default scram_iterations count, because the authentication challenge for a nonexistent user reports the default scram_iterations. Within major versions 16-18, minor versions before PostgreSQL 18.5, 17.11, and 16.15 are affected. Versions before PostgreSQL 16 are unaffected.

CVSS3: 5.3
0%
Низкий
около 1 месяца назад
ubuntu логотип
CVE-2026-14672

Observable response discrepancy in PostgreSQL SCRAM authentication allows an unauthenticated user to test the existence of a user via observing the SCRAM iteration count. This requires the probed user to have a non-default scram_iterations count, because the authentication challenge for a nonexistent user reports the default scram_iterations. Within major versions 16-18, minor versions before PostgreSQL 18.6, 17.11, and 16.15 are affected. Versions before PostgreSQL 16 are unaffected.

CVSS3: 5.3
0%
Низкий
около 1 месяца назад
redhat логотип
CVE-2026-14672

Observable response discrepancy in PostgreSQL SCRAM authentication allows an unauthenticated user to test the existence of a user via observing the SCRAM iteration count. This requires the probed user to have a non-default scram_iterations count, because the authentication challenge for a nonexistent user reports the default scram_iterations. Within major versions 16-18, minor versions before PostgreSQL 18.5, 17.11, and 16.15 are affected. Versions before PostgreSQL 16 are unaffected.

CVSS3: 5.3
0%
Низкий
около 1 месяца назад
nvd логотип
CVE-2026-14672

Observable response discrepancy in PostgreSQL SCRAM authentication allows an unauthenticated user to test the existence of a user via observing the SCRAM iteration count. This requires the probed user to have a non-default scram_iterations count, because the authentication challenge for a nonexistent user reports the default scram_iterations. Within major versions 16-18, minor versions before PostgreSQL 18.6, 17.11, and 16.15 are affected. Versions before PostgreSQL 16 are unaffected.

CVSS3: 5.3
0%
Низкий
около 1 месяца назад
msrc логотип
CVE-2026-14672

PostgreSQL observable response discrepancy with non-default scram_iterations provides user existence oracle

CVSS3: 5.3
0%
Низкий
29 дней назад
debian логотип
CVE-2026-14672

Observable response discrepancy in PostgreSQL SCRAM authentication all ...

CVSS3: 5.3
0%
Низкий
около 1 месяца назад
fstec логотип
BDU:2026-11958

Уязвимость подсистемы аутентификации SCRAM системы управления базами данных PostgreSQL, позволяющая нарушителю раскрыть защищаемую информацию

CVSS3: 5.3
0%
Низкий
около 1 месяца назад
suse-cvrf логотип
openSUSE-SU-2026:21702-1

Security update for postgresql17

22 дня назад
suse-cvrf логотип
openSUSE-SU-2026:21701-1

Security update for postgresql16

22 дня назад
suse-cvrf логотип
SUSE-SU-2026:4016-1

Security update for postgresql17

15 дней назад
suse-cvrf логотип
SUSE-SU-2026:4013-1

Security update for postgresql17

15 дней назад
suse-cvrf логотип
SUSE-SU-2026:3963-1

Security update for postgresql16

19 дней назад
suse-cvrf логотип
SUSE-SU-2026:3943-1

Security update for postgresql16

19 дней назад
suse-cvrf логотип
SUSE-SU-2026:3794-1

Security update for postgresql16

28 дней назад
suse-cvrf логотип
openSUSE-SU-2026:21703-1

Security update for postgresql18

22 дня назад
suse-cvrf логотип
SUSE-SU-2026:4015-1

Security update for postgresql18

15 дней назад
suse-cvrf логотип
SUSE-SU-2026:4014-1

Security update for postgresql18

15 дней назад
suse-cvrf логотип
SUSE-SU-2026:3942-1

Security update for postgresql18

19 дней назад

Уязвимостей на страницу