216.73.216.31

CVE-2025-49146

· Published 11/06/2025 15:15 · Modified 12/06/2025 16:06

Labels: CVE-2025-49146 2025-06-11CVE-2025-49146CWE-287[email protected]

Essential information

Published
11/06/2025 15:15
Modified
12/06/2025 16:06
Author
Creator
CVSS
8.2 HIGH (v3.1)
CISA KEV
No
CWE
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N

CVSS metrics

Description

pgjdbc is an open source postgresql JDBC Driver. From 42.7.4 and until 42.7.7, when the PostgreSQL JDBC driver is configured with channel binding set to required (default value is prefer), the driver would incorrectly allow connections to proceed with authentication methods that do not support channel binding (such as password, MD5, GSS, or SSPI authentication). This could allow a man-in-the-middle attacker to intercept connections that users believed were protected by channel binding requirements. This vulnerability is fixed in 42.7.7.

NVD status

Status
Awaiting Analysis — CVE has been recently published to the CVE List and has been received by the NVD.
Source
[email protected]
NVD
View on NVD

Affected products (CPE)

ProductCPE
postgresql / pgjdbc cpe:2.3:a:postgresql:pgjdbc:42.7.4-42.7.7:*:*:*:*:*:*:*

References