Lucene search

K
nvd[email protected]NVD:CVE-2023-22332
HistoryJan 30, 2023 - 7:15 a.m.

CVE-2023-22332

2023-01-3007:15:10
CWE-312
web.nvd.nist.gov
3
pgpool-ii
information disclosure
vulnerability
database
authentication
remote attacker

CVSS3

6.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

AI Score

6.3

Confidence

High

EPSS

0.001

Percentile

44.0%

Information disclosure vulnerability exists in Pgpool-II 4.4.0 to 4.4.1 (4.4 series), 4.3.0 to 4.3.4 (4.3 series), 4.2.0 to 4.2.11 (4.2 series), 4.1.0 to 4.1.14 (4.1 series), 4.0.0 to 4.0.21 (4.0 series), All versions of 3.7 series, All versions of 3.6 series, All versions of 3.5 series, All versions of 3.4 series, and All versions of 3.3 series. A specific database user’s authentication information may be obtained by another database user. As a result, the information stored in the database may be altered and/or database may be suspended by a remote attacker who successfully logged in the product with the obtained credentials.

Affected configurations

Nvd
Node
pgpoolpgpool-iiRange3.3.03.7.12
OR
pgpoolpgpool-iiRange4.0.04.0.22
OR
pgpoolpgpool-iiRange4.1.04.1.15
OR
pgpoolpgpool-iiRange4.2.04.2.12
OR
pgpoolpgpool-iiRange4.3.04.3.5
OR
pgpoolpgpool-iiRange4.4.04.4.2
VendorProductVersionCPE
pgpoolpgpool-ii*cpe:2.3:a:pgpool:pgpool-ii:*:*:*:*:*:*:*:*

CVSS3

6.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

AI Score

6.3

Confidence

High

EPSS

0.001

Percentile

44.0%