Replication Vulnerability in pglogical by EDB
CVE-2025-2506

5.3MEDIUM

Key Information:

Vendor
CVE Published:
22 May 2025

What is CVE-2025-2506?

This vulnerability arises in the pglogical component of EDB's database systems, where it fails to ensure that incoming connections are verified as replication connections. Consequently, any user with CONNECT permissions to a database set up for replication could execute pglogical commands. This oversight opens up the possibility for unauthorized users to gain read access to sensitive replicated tables, thereby compromising data integrity and confidentiality. Attackers must possess knowledge of specific pglogical and BDR commands alongside the ability to decode a binary protocol to exploit this weakness effectively.

Affected Version(s)

BDR/PGD 4

BDR/PGD 5

pglogical 3

References

CVSS V3.1

Score:
5.3
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-2506 : Replication Vulnerability in pglogical by EDB