CVE-2020-13692XML External Entity (XXE) Injection in Postgresql Jdbc Driver

Severity
7.7HIGHNVD
EPSS
7.8%
top 8.01%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJun 4
Latest updateSep 6

Description

PostgreSQL JDBC Driver (aka PgJDBC) before 42.2.13 allows XXE.

CVSS vector

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:L/A:HExploitability: 2.2 | Impact: 5.5

Affected Packages2 packages

Also affects: Debian Linux 10.0, 11.0, Fedora 32

Patches

🔴Vulnerability Details

4
GHSA
Improper Restriction of XML External Entity Reference2022-02-10
OSV
Improper Restriction of XML External Entity Reference2022-02-10
OSV
CVE-2020-13692: PostgreSQL JDBC Driver (aka PgJDBC) before 422020-06-04
CVEList
CVE-2020-13692: PostgreSQL JDBC Driver (aka PgJDBC) before 422020-06-04

📋Vendor Advisories

3
Ubuntu
PostgreSQL JDBC Driver vulnerability2022-09-06
Red Hat
postgresql-jdbc: XML external entity (XXE) vulnerability in PgSQLXML2020-06-04
Debian
CVE-2020-13692: libpgjava - PostgreSQL JDBC Driver (aka PgJDBC) before 42.2.13 allows XXE.2020

💬Community

2
Bugzilla
CVE-2020-13692 postgresql-jdbc: XML external entity (XXE) vulnerability in PgSQLXML [fedora-all]2020-07-28
Bugzilla
CVE-2020-13692 postgresql-jdbc: XML external entity (XXE) vulnerability in PgSQLXML2020-07-01
CVE-2020-13692 — XML External Entity (XXE) Injection | cvebase