Skip to content

Moderate severity vulnerability that affects org.postgresql:pgjdbc-aggregate

Moderate severity GitHub Reviewed Published Oct 19, 2018 to the GitHub Advisory Database • Updated Jan 9, 2023

Package

maven org.postgresql:pgjdbc-aggregate (Maven)

Affected versions

< 42.2.5

Patched versions

42.2.5

Description

A weakness was found in postgresql-jdbc before version 42.2.5. It was possible to provide an SSL Factory and not check the host name if a host name verifier was not provided to the driver. This could lead to a condition where a man-in-the-middle attacker could masquerade as a trusted server by providing a certificate for the wrong host, as long as it was signed by a trusted CA.

References

Published to the GitHub Advisory Database Oct 19, 2018
Reviewed Jun 16, 2020
Last updated Jan 9, 2023

Severity

Moderate

Weaknesses

CVE ID

CVE-2018-10936

GHSA ID

GHSA-568q-9fw5-28wf

Source code

No known source code
Loading Checking history
See something to contribute? Suggest improvements for this vulnerability.