Description
pgsync before 0.6.7 is affected by Information Disclosure of sensitive information. Syncing the schema with the --schema-first and --schema-only options is mishandled. For example, the sslmode connection parameter may be lost, which means that SSL would not be used.
References
https://github.com/ankane/pgsync/issues/121
ExploitIssue TrackingThird Party Advisory
https://github.com/ankane/pgsync/issues/121
ExploitIssue TrackingThird Party Advisory
CVSS impact metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
7.5 · High
Information
Source identifier
Vulnerability status
Modified
Published
2021-04-27T01:15:07.647Z
4 years agoLast modified
2024-11-21T05:06:06.230Z
1 year ago