PT-2024-31713 · Pgpool-Ii+3 · Pgpool-Ii+3

Published

2024-09-09

·

Updated

2025-10-28

·

CVE-2024-45624

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:C/I:N/A:N
Name of the Vulnerable Software and Affected Versions: Pgpool-II versions up to 4.5.3
Description: Exposure of sensitive information due to incompatible policies issue exists in Pgpool-II. If a database user accesses a query cache, table data unauthorized for the user may be retrieved.
Recommendations: For Pgpool-II versions up to 4.5.3, upgrade to a patched version immediately to prevent sensitive data exposure. As a temporary workaround, consider restricting access to the query cache to minimize the risk of exploitation.

Fix

Information Disclosure

Weakness Enumeration

Related Identifiers

BDU:2025-08025
CVE-2024-45624
DLA-3993-1
DSA-5974-1

Affected Products

Astra Linux
Debian
Pgpool-Ii
Red Os