cbcvebase.
CVE-2020-25694
published 2020-11-16

CVE-2020-25694: A flaw was found in PostgreSQL versions before 13.1, before 12.5, before 11.10, before 10.15, before 9.6.20 and before 9.5.24. If a client application that…

PriorityP346high8.1CVSS 3.1
AVNACHPRNUINSUCHIHAH
EPSS
1.57%
72.7th percentile
A flaw was found in PostgreSQL versions before 13.1, before 12.5, before 11.10, before 10.15, before 9.6.20 and before 9.5.24. If a client application that creates additional database connections only reuses the basic connection parameters while dropping security-relevant parameters, an opportunity for a man-in-the-middle attack, or the ability to observe clear-text transmissions, could exist. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.

Affected

10 ranges
VendorProductVersion rangeFixed in
debiandebian_linux
debianpostgresql-13< postgresql-13 13.1-1 (bullseye)postgresql-13 13.1-1 (bullseye)
msrccm1_postgresql_12.7-1_on_cbl_mariner_1.0
postgresqlpostgresql< 9.5.249.5.24
postgresqlpostgresql
postgresqlpostgresql>= 10.0 < 10.1510.15
postgresqlpostgresql>= 11.0 < 11.1011.10
postgresqlpostgresql>= 12.0 < 12.512.5
postgresqlpostgresql>= 13.0 < 13.113.1
postgresqlpostgresql>= 9.6.0 < 9.6.209.6.20

CVSS provenance

nvdv3.18.1HIGHCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
osv8.1HIGH
vendor_debian8.1HIGH
vendor_msrc8.1HIGH
vendor_redhat8.1HIGH
vendor_ubuntu8.1HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.