Man-in-the-Middle Vulnerability in PostgreSQL by PostgreSQL Global Development Group
CVE-2020-25694
8.1HIGH
Summary
PostgreSQL versions prior to 13.1, 12.5, 11.10, 10.15, 9.6.20, and 9.5.24 are susceptible to a flaw that could allow attackers to exploit weakened connection settings. This occurs when client applications drop security-critical connection parameters, potentially enabling a man-in-the-middle attack. As a result, sensitive data in transit could be intercepted, compromising both confidentiality and integrity, and threatening system availability.
Affected Version(s)
postgresql All PostgreSQL versions before 13.1, before 12.5, before 11.10, before 10.15, before 9.6.20 and before 9.5.24
References
CVSS V3.1
Score:
8.1
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved