pgjdbc(PostgreSQL JDBC 驱动程序)在版本 42.7.11 至 42.7.13 中存在安全漏洞。当配置 连接属性以排除驱动程序所知的所有六种认证方法时(例如: ),驱动程序未施加任何限制。此时,驱动程序将接受服务器请求的任何认证方法,包括明文密码认证。此外,不包含任何认证方法值的配置(如 或单个逗号 )也会受到相同影响。 处于应用程序与数据库服务器之间的攻击者可以强制要求使用明文密码认证,并窃取数据库密码。而使用正向白名单方式(如 )或部分排除方式(如 )的 属性值则会按预期正确生效。 该 属性
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-107315 | 5.3 MEDIUM | pgjdbc pads a value shorter than its declared length with bytes of earlier statements (rat |
| CVE-2026-107313 | 4.2 MEDIUM | pgjdbc stores bytes of earlier messages in place of a large value on GSS-encrypted connect |
No comments yet