Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
Silent channel-binding authentication downgrade via unsupported certificate algorithms
Vulnerability Description
pgjdbc is an open source postgresql JDBC Driver. In releases 42.7.4 through 42.7.11, channelBinding=require connections can be silently downgraded from SCRAM-SHA-256-PLUS with channel binding to plain SCRAM-SHA-256 without it, losing the man-in-the-middle protection the setting is meant to guarantee. An attacker who can intercept the TLS connection can trigger the downgrade with a certificate whose signature algorithm has no tls-server-end-point channel-binding hash, because the bundled com.ongres.scram:scram-client returns an empty byte array instead of failing and pgJDBC ScramAuthenticator checks only that the server advertised a PLUS mechanism, without rejecting the empty binding or checking that the negotiated mechanism uses channel binding. This issue is fixed in version 42.7.12.
CVSS Information
CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:L/SA:N
Vulnerability Type
未能安全地进行程序失效(Failing Open)
Vulnerability Title
PostgreSQL JDBC Driver 异常处理不当漏洞
Vulnerability Description
PostgreSQL JDBC Driver是PostgreSQL组织开源的一个JDBC驱动程序。 PostgreSQL JDBC Driver 42.7.12之前版本存在安全漏洞,该漏洞源于异常处理不当和加密问题,可能导致攻击者通过拦截TLS连接触发channelBinding=require连接从SCRAM-SHA-256-PLUS降级到普通SCRAM-SHA-256丢失中间人保护。
CVSS Information
N/A
Vulnerability Type
N/A