PT-2017-7049 · Pgbouncer · Pgbouncer

Published

2017-05-23

·

Updated

2020-11-03

·

CVE-2015-6817

CVSS v3.1

8.1

High

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions PgBouncer versions 1.6.x before 1.6.1
Description The issue allows remote attackers to gain login access as auth user via an unknown username when PgBouncer is configured with auth user.
Recommendations For PgBouncer versions 1.6.x before 1.6.1, update to version 1.6.1 or later to resolve the issue.

Fix

Improper Authentication

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2015-6817

Affected Products

Pgbouncer