Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:39220
HistoryFeb 11, 2023 - 11:04 p.m.

Information Disclosure

2023-02-1123:04:31
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
9
postgresql vulnerability
information disclosure
kerberos encryption
software vulnerability
unauthenticated server
libpq caller
attacker access

0.001 Low

EPSS

Percentile

34.6%

postgresql is vulnerable to Information Disclosure. The vulnerability exists because a modified, unauthenticated server can send an unterminated string during the establishment of kerberos transport encryption where a libpq’s caller makes that message accessible to the attacker.