Replication Vulnerability in pglogical by EDB
CVE-2025-2506
5.3MEDIUM
What is CVE-2025-2506?
This vulnerability arises in the pglogical component of EDB's database systems, where it fails to ensure that incoming connections are verified as replication connections. Consequently, any user with CONNECT permissions to a database set up for replication could execute pglogical commands. This oversight opens up the possibility for unauthorized users to gain read access to sensitive replicated tables, thereby compromising data integrity and confidentiality. Attackers must possess knowledge of specific pglogical and BDR commands alongside the ability to decode a binary protocol to exploit this weakness effectively.
Affected Version(s)
BDR/PGD 4
BDR/PGD 5
pglogical 3
