PT-2021-19473 · Pgsync · Pgsync

Dmitry Gunchenko

·

Published

2021-04-27

·

Updated

2021-05-04

·

CVE-2021-31671

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions pgsync versions prior to 0.6.7
Description The issue concerns the mishandling of syncing the schema with the --schema-first and --schema-only options, leading to information disclosure of sensitive information. For example, the sslmode connection parameter may be lost, resulting in SSL not being used.
Recommendations For versions prior to 0.6.7, update to version 0.6.7 or later to resolve the issue. As a temporary workaround, consider avoiding the use of the --schema-first and --schema-only options until a patch is applied. Restrict access to sensitive information to minimize the risk of exploitation.

Exploit

Fix

Cleartext Transmission of Sensitive Information

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2021-31671
GHSA-72RJ-36QC-47G7

Affected Products

Pgsync