漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
Silent channel-binding authentication downgrade via unsupported certificate algorithms
Vulnerability Description
pgjdbc is an open source postgresql JDBC Driver. In releases 42.7.4 through 42.7.11, channelBinding=require connections can be silently downgraded from SCRAM-SHA-256-PLUS with channel binding to plain SCRAM-SHA-256 without it, losing the man-in-the-middle protection the setting is meant to guarantee. An attacker who can intercept the TLS connection can trigger the downgrade with a certificate whose signature algorithm has no tls-server-end-point channel-binding hash, because the bundled com.ongres.scram:scram-client returns an empty byte array instead of failing and pgJDBC ScramAuthenticator checks only that the server advertised a PLUS mechanism, without rejecting the empty binding or checking that the negotiated mechanism uses channel binding. This issue is fixed in version 42.7.12.
CVSS Information
CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:L/SA:N
Vulnerability Type
未能安全地进行程序失效(Failing Open)
Vulnerability Title
PostgreSQL JDBC Driver 异常处理不当漏洞
Vulnerability Description
PostgreSQL JDBC Driver是PostgreSQL组织开源的一个JDBC驱动程序。 PostgreSQL JDBC Driver 42.7.12之前版本存在安全漏洞,该漏洞源于异常处理不当和加密问题,可能导致攻击者通过拦截TLS连接触发channelBinding=require连接从SCRAM-SHA-256-PLUS降级到普通SCRAM-SHA-256丢失中间人保护。
CVSS Information
N/A
Vulnerability Type
N/A