HIGH🇬🇧 English

CVE-2025-49146

CVSS 8.2v3.1pub. 2025-06-11upd. 2025-10-06

pgjdbc is an open source postgresql JDBC Driver. From 42.7.4 and until 42.7.7, when the PostgreSQL JDBC driver is configured with channel binding set to required (default value is prefer), the driver would incorrectly allow connections to proceed with authentication methods that do not support channel binding (such as password, MD5, GSS, or SSPI authentication). This could allow a man-in-the-middle attacker to intercept connections that users believed were protected by channel binding requirements. This vulnerability is fixed in 42.7.7.

oryginał EN
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N
  • PostgreSQL Jdbc Driver

    APP
    Postgresql
    42.7.4 – 42.7.7 (bez)
🔵
ZWERYFIKUJ U PRODUCENTA
Brak jednoznacznych danych o patchu. Sprawdź referencje od producenta.
Tagi
Auth Bypass
CWE
Referencje

Powiązane podatności

CVE-2024-1597CRITICAL10.0PL ✓ten sam produkt

SQL Injection w PostgreSQL JDBC Driver (pgjdbc) — tryb SIMPLE

CVE-2022-26520CRITICAL9.8PL ✓ten sam produkt

Zapis do dowolnych plików przez pgjdbc via loggerFile (przed 42.3.3)

CVE-2026-54291HIGH8.2PL ✓ten sam produkt

Cicha degradacja channel binding w PostgreSQL JDBC Driver (pgjdbc)

CVE-2026-42198HIGH7.5ten sam produkt

pgjdbc is an open source postgresql JDBC Driver. From version 42.2.0 to before version 42.7.11, pgjdbc is vuln...

CVE-2022-31197HIGH7.1ten sam produkt

PostgreSQL JDBC Driver (PgJDBC for short) allows Java programs to connect to a PostgreSQL database using stand...