Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:38225
HistoryNov 24, 2022 - 7:01 a.m.

Information Disclosure

2022-11-2407:01:27
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
20
postgresql
jdbc driver
information disclosure
vulnerable
streamwrapper
file permissions.

EPSS

0.001

Percentile

23.5%

Postgresql JDBC Driver is vulnerable to Information Disclosure. The vulnerability exists due to StreamWrapper parameterized constructor in StreamWrapper.java creating a temporary file if the InputStream is larger than 51200 bytes which allows an attacker to read the file due to incorrect file permissions.

References