AI description
CVE-2025-49146 affects the open-source PostgreSQL JDBC driver (pgjdbc). Specifically, versions 42.7.4 up to 42.7.7 are vulnerable. The vulnerability arises when the driver is configured with channel binding set to "required" (the default is "prefer"). In this configuration, the driver incorrectly permits connections to proceed using authentication methods that do not support channel binding, such as password, MD5, GSS, or SSPI. This flaw could allow a man-in-the-middle attacker to intercept connections that users believed were protected by channel binding requirements. The vulnerability is fixed in version 42.7.7.
- Description
- pgjdbc is an open source postgresql JDBC Driver. From 42.7.4 and until 42.7.7, when the PostgreSQL JDBC driver is configured with channel binding set to required (default value is prefer), the driver would incorrectly allow connections to proceed with authentication methods that do not support channel binding (such as password, MD5, GSS, or SSPI authentication). This could allow a man-in-the-middle attacker to intercept connections that users believed were protected by channel binding requirements. This vulnerability is fixed in 42.7.7.
- Source
- security-advisories@github.com
- NVD status
- Awaiting Analysis
CVSS 3.1
- Type
- Secondary
- Base score
- 8.2
- Impact score
- 4.2
- Exploitability score
- 3.9
- Vector string
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N
- Severity
- HIGH
- security-advisories@github.com
- CWE-287
- Hype score
- Not currently trending
News: PostgreSQL JDBC 42.7.7 Security update for CVE-2025-49146 https://t.co/9XKyLh2AHM
@PostgreSQL
13 Jun 2025
1377 Impressions
1 Retweet
10 Likes
2 Bookmarks
0 Replies
0 Quotes
PostgreSQLのJDBCドライバ(PgJDBC)に新たな脆弱性(CVE-2025-49146)が発見され、JavaアプリケーションとPostgreSQL間の安全な通信が危険にさらされている。
@yousukezan
13 Jun 2025
809 Impressions
0 Retweets
4 Likes
0 Bookmarks
0 Replies
0 Quotes
CVE-2025-49146 pgjdbc is an open source postgresql JDBC Driver. From 42.7.4 and until 42.7.7, when the PostgreSQL JDBC driver is configured with channel binding set to required (def… https://t.co/LC4M8Nd5yK
@CVEnew
11 Jun 2025
291 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes