Man-in-the-Middle Vulnerability in PostgreSQL by PostgreSQL Global Development Group
CVE-2020-25694

8.1HIGH

Key Information:

Vendor
Postgresql
Vendor
CVE Published:
16 November 2020

Summary

PostgreSQL versions prior to 13.1, 12.5, 11.10, 10.15, 9.6.20, and 9.5.24 are susceptible to a flaw that could allow attackers to exploit weakened connection settings. This occurs when client applications drop security-critical connection parameters, potentially enabling a man-in-the-middle attack. As a result, sensitive data in transit could be intercepted, compromising both confidentiality and integrity, and threatening system availability.

Affected Version(s)

postgresql All PostgreSQL versions before 13.1, before 12.5, before 11.10, before 10.15, before 9.6.20 and before 9.5.24

References

CVSS V3.1

Score:
8.1
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.