Description
A weakness was found in postgresql-jdbc before version 42.2.5. It was possible to provide an SSL Factory and not check the host name if a host name verifier was not provided to the driver. This could lead to a condition where a man-in-the-middle attacker could masquerade as a trusted server by providing a certificate for the wrong host, as long as it was signed by a trusted CA.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2018-0508 | A weakness was found in postgresql-jdbc before version 42.2.5. It was possible to provide an SSL Factory and not check the host name if a host name verifier was not provided to the driver. This could lead to a condition where a man-in-the-middle attacker could masquerade as a trusted server by providing a certificate for the wrong host, as long as it was signed by a trusted CA. |
Github GHSA |
GHSA-568q-9fw5-28wf | Moderate severity vulnerability that affects org.postgresql:pgjdbc-aggregate |
References
History
No history.
Status: PUBLISHED
Assigner: redhat
Published:
Updated: 2024-08-05T07:54:36.516Z
Reserved: 2018-05-09T00:00:00.000Z
Link: CVE-2018-10936
No data.
Status : Modified
Published: 2018-08-30T13:29:00.377
Modified: 2024-11-21T03:42:20.793
Link: CVE-2018-10936
OpenCVE Enrichment
No data.
Weaknesses
EUVD
Github GHSA