V
Scaner-VS
HomeCatalogSourcesCWECAPECATT&CKMitigationsDocs
CVE-2022-21724
DEB
High

pgjdbc is the offical PostgreSQL JDBC Driver. A security hole was found in the jdbc driver for postgresql database while doing security res…

CVSS
7.0
High
EPSS
0.04
p88
Published
2022-01-01
Updated
2022-01-01
Description

pgjdbc is the offical PostgreSQL JDBC Driver. A security hole was found in the jdbc driver for postgresql database while doing security research. The system using the postgresql library will be attacked when attacker control the jdbc url or properties. pgjdbc instantiates plugin instances based on class names provided via `authenticationPluginClassName`, `sslhostnameverifier`, `socketFactory`, `sslfactory`, `sslpasswordcallback` connection properties. However, the driver did not verify if the class implements the expected interface before instantiating the class. This can lead to code execution loaded via arbitrary classes. Users using plugins are advised to upgrade. There are no known workarounds for this issue.

Tags · CWE
Pre-auth
CWE-665
CAPEC-26
CAPEC-29
Affected products
Debian_linux
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Timeline
2022-01-01
Published
2022-01-01
Updated
CVSS 3.1 breakdown
Attack Vector
AV: N
Network (N)
Attack Complexity
AC: L
Low (L)
Privileges Required
PR: N
None (N)
User Interaction
UI: N
None (N)
Scope
S: U
Unchanged (U)
Confidentiality Impact
C: H
High (H)
Integrity Impact
I: H
High (H)
Availability Impact
A: H
High (H)
Exploit indicators
EPSS
0.041 · p88
Known exploited (KEV)
No
Known exploits — Сканер-ВС
No Сканер-ВС checks registered for this vulnerability yet.
Affected software
ProductVendorStatus
libpgjavaTracked
libpgjavaTracked
libpgjavaTracked
libpgjavaTracked
libpgjavaTracked
libpgjavaTracked
libpgjavaTracked
libpgjavaTracked
libpgjavaTracked
libpgjavaTracked
libpgjavaTracked
libpgjavaTracked
libpgjavaTracked
postgresql-jdbcTracked
postgresql-jdbc-javadocTracked
debian_linux*Tracked
fedora*Tracked
postgresql_jdbc_driver*Tracked
quarkus*Tracked
Source databases
DEB
CVE
RED
UBU
Related vulnerabilities