Bug 2372307 (CVE-2025-49146)
Summary: | CVE-2025-49146 pgjdbc: pgjdbc insecure authentication in channel binding | ||
---|---|---|---|
Product: | [Other] Security Response | Reporter: | OSIDB Bzimport <bzimport> |
Component: | vulnerability | Assignee: | Product Security DevOps Team <prodsec-dev> |
Status: | NEW --- | QA Contact: | |
Severity: | high | Docs Contact: | |
Priority: | high | ||
Version: | unspecified | CC: | aazores, anstephe, anthomas, aprice, aschwart, asoldano, ataylor, avibelli, bbaranow, bgeorges, bmaxwell, boliveir, brian.stansberry, caswilli, ccranfor, cdewolf, clement.escoffier, cmah, cmiranda, dandread, darran.lofthouse, dbruscin, dhanak, dkreling, dnakabaa, dosoudil, drosa, eaguilar, ebaron, ehelms, eric.wittmann, fjuma, fmariani, ggainey, gmalinko, gsmet, ibek, istudens, ivassile, iweiss, janstey, jmartisk, jolong, jpechane, jpoth, jrokos, jross, jsamir, juwatts, kaycoth, kgaikwad, kholdawa, kvanderr, kverlaen, lcouzens, lgao, lthon, manderse, mhulan, mnovotny, mosmerov, mposolda, mskarbek, msochure, msvehla, nipatil, nmoumoul, nwallace, oezr, olubyans, osousa, pantinor, pbizzarr, pcongius, pcreech, pdelbell, pesilva, pgallagh, pjindal, pmackay, probinso, rchan, rkieley, rkubis, rruss, rstancel, rstepani, rsvoboda, sausingh, sbiarozk, sdawley, smaestri, smallamp, ssilvert, sthirugn, sthorger, tcunning, tom.jenkinson, tqvarnst, vkrizan, vmuzikar, yfang |
Target Milestone: | --- | Keywords: | Security |
Target Release: | --- | ||
Hardware: | All | ||
OS: | Linux | ||
Whiteboard: | |||
Fixed In Version: | Doc Type: | --- | |
Doc Text: |
A connection handling flaw was found in the pgjdbc connection driver in configurations that require channel binding. Connections created with authentication methods that should not allow channel binding permit connections to use channel binding. This flaw allows attackers to position themselves in the middle of a connection and intercept the connection.
|
Story Points: | --- |
Clone Of: | Environment: | ||
Last Closed: | Type: | --- | |
Regression: | --- | Mount Type: | --- |
Documentation: | --- | CRM: | |
Verified Versions: | Category: | --- | |
oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
Cloudforms Team: | --- | Target Upstream Version: | |
Embargoed: |
Description
OSIDB Bzimport
2025-06-11 15:01:57 UTC
|