ZeroHour

CVE-2021-3935

CVSS 3.1
8.1 high
EPSS
1%p62
Published
()
Modified
Description

When PgBouncer is configured to use "cert" authentication, a man-in-the-middle attacker can inject arbitrary SQL queries when a connection is first established, despite the use of TLS certificate verification and encryption. This flaw affects PgBouncer versions prior to 1.16.1.

Vendors
pgbouncerredhatfedoraprojectdebian
Products
pgbouncer, enterprise linux, fedora, debian linux
Weakness
CWE-89, CWE-295
Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.