PT-2017-7049 · Pgbouncer · Pgbouncer

Publicado

2017-05-23

·

Atualizado

2020-11-03

·

CVE-2015-6817

CVSS v3.1

8.1

Alta

VetorAV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions PgBouncer versions 1.6.x before 1.6.1
Description The issue allows remote attackers to gain login access as auth user via an unknown username when PgBouncer is configured with auth user.
Recommendations For PgBouncer versions 1.6.x before 1.6.1, update to version 1.6.1 or later to resolve the issue.

Correção

Improper Authentication

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2015-6817

Produtos afetados

Pgbouncer