Lucene search

K
jvnJapan Vulnerability NotesJVN:72418815
HistoryJan 23, 2023 - 12:00 a.m.

JVN#72418815: Pgpool-II vulnerable to information disclosure

2023-01-2300:00:00
Japan Vulnerability Notes
jvn.jp
13
pgpool-ii
vulnerability
information disclosure
cwe-200
watchdog function
password
authentication
database
software update
workaround
encryption
aes
heartbeat
version
security advisory

CVSS3

6.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

EPSS

0.001

Percentile

44.0%

Pgpool-II is cluster management tool. Pgpool-II contains an information disclosure vulnerability (CWE-200) in its watchdog function.
Note that, only systems that meet all of the following setting requirements are affected by this vulnerability.

Watchdog function is enabled (use_watchdog = on) “query mode” is used for the alive monitoring of watchdog (wd_lifecheck_method = 'query') Plain text password is set for wd_lifecheck_password

Impact

A specific database user’s authentication information may be obtained by another database user.
As a result, the information stored in the database may be altered and/or database may be suspended by an attacker who logged in with the obtained credentials.

Solution

Update the Software
Update to the latest version according to the information provided by the developer.
The developer has released the following versions that address the vulnerability.

  • Pgpool-II 4.4.2 (4.4 series)
  • Pgpool-II 4.3.5 (4.3 series)
  • Pgpool-II 4.2.12 (4.2 series)
  • Pgpool-II 4.1.15 (4.1 series)
  • Pgpool-II 4.0.22 (4.0 series)
    The developer recommends users to upgrade the software to 4.0 series or later, as 3.3 to 3.7 series are no longer supported (End-of-Support), and no updates/patches are provided for them.

Apply the workaround
Applying the following workarounds may mitigate the impacts of this vulnerability.
Pgpool-II 3.3 series to 3.7 series

  • Stop using watchdog function (use_watchdog = off)

  • Set as follows:

    • wd_lifecheck_method = 'heartbeat'
      Pgpool-II 4.0 series to 4.4 series
  • Stop using watchdog function (use_watchdog = off)

  • Set as follows:

    • wd_lifecheck_method = 'heartbeat'
  • Set encrypted password with AES for wd_lifecheck_password

  • Set null characters for wd_lifecheck_password and the password to pool_passwd file

Products Affected

The following versions of Pgpool-II are affected:

  • 4.4.0 to 4.4.1 (4.4 series)
  • 4.3.0 to 4.3.4 (4.3 series)
  • 4.2.0 to 4.2.11 (4.2 series)
  • 4.1.0 to 4.1.14 (4.1 series)
  • 4.0.0 to 4.0.21 (4.0 series)
  • All versions of 3.7 series
  • All versions of 3.6 series
  • All versions of 3.5 series
  • All versions of 3.4 series
  • All versions of 3.3 series

CVSS3

6.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

EPSS

0.001

Percentile

44.0%