Lucene search

K
redhatcveRedhat.comRH:CVE-2017-7485
HistoryOct 10, 2019 - 4:31 a.m.

CVE-2017-7485

2019-10-1004:31:59
redhat.com
access.redhat.com
10

0.005 Low

EPSS

Percentile

76.5%

It was discovered that the PostgreSQL client library (libpq) did not enforce the use of TLS/SSL for a connection to a PostgreSQL server when the PGREQUIRESSL environment variable was set. An man-in-the-middle attacker could use this flaw to strip the SSL/TLS protection from a connection between a client and a server.

Mitigation

Use PGSSLMODE=require instead of PGREQUIRESSL=1