CVE-2020-17446
—CVSS 3.1
9.8 critical
EPSS
2%p83
Published
()
Modified
Description
asyncpg before 0.21.0 allows a malicious PostgreSQL server to trigger a crash or execute arbitrary code (on a database client) via a crafted server response, because of access to an uninitialized pointer in the array data decoder.
In the news0 stories
No ingested article mentions this CVE yet.