Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:13010
HistoryJan 15, 2019 - 9:24 a.m.

Authorization Bypass

2019-01-1509:24:38
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
12

EPSS

0.003

Percentile

66.0%

postgresql is vulnerable to authorization bypass. An attacker is able to bypass client-side connection security features to escalate privileges, execute arbitrary SQL statements. This is due to the failure of the client library to properly reset its internal state between connections, which leads to the malfunction of the PQescape() function.