pgjdbc(PostgreSQL JDBC 驱动程序)版本 42.7.4 和 42.7.5 存在以下安全问题: 在使用 GSS 加密的连接上(当配置 gssEncMode 为 “prefer” 或 “require” 时),驱动程序可能会将 GSS 发送缓冲区中先前缓存的内容,错误地替换为值的前半部分,而服务器在接受该值时未报错。在 MIT Kerberos 环境下,该缓冲区大小为 16320 字节。因此,存储的值可能包含驱动程序在此之前在同一连接上发送的消息中的字节,例如 SQL 语句文本、其他参数以及同一批量
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-107314 | 5.9 MEDIUM | pgjdbc does not enforce requireAuth when the value excludes every authentication method |
| CVE-2026-107315 | 5.3 MEDIUM | pgjdbc pads a value shorter than its declared length with bytes of earlier statements (rat |
No comments yet