PT-2025-25224 · Pgjdbc+2 · Pgjdbc+4
Jawj
·
Published
2025-06-11
·
Updated
2026-01-20
·
CVE-2025-49146
CVSS v2.0
8.5
High
| Vector | AV:N/AC:L/Au:N/C:C/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
pgjdbc versions 42.7.4 through 42.7.6
Description
The issue arises when the PostgreSQL JDBC driver is configured with channel binding set to
required, allowing connections to proceed with authentication methods that do not support channel binding, such as password, MD5, GSS, or SSPI authentication. This could enable a man-in-the-middle attacker to intercept connections that users believed were protected by channel binding requirements.Recommendations
For pgjdbc versions 42.7.4 through 42.7.6, update to version 42.7.7 to resolve the issue.
As a temporary workaround, consider configuring
sslMode=verify-full to prevent man-in-the-middle attacks.Exploit
Fix
Improper Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Bamboo
Bitbucket
Confluence
Debian
Pgjdbc