{"id":"CVE-2009-3231","year":2009,"sequence":3231,"component":"","score":null,"cvss_version":"","vector":"","first_published":null,"source_url":"https://www.postgresql.org/support/security/CVE-2009-3231/","facts":{"affected":{"8.2":"8.2","8.3":"8.3"},"component":"","cvss_version":"","description_en":"","first_published":null,"fixed":{"8.2":"8.2.14","8.3":"8.3.8"},"id":"CVE-2009-3231","introduced":{},"published":{},"score":null,"title":"If PostgreSQL is configured with LDAP authentication, and your LDAP configuration allows anonymous binds, it is possible for a user to authenticate themselves with an empty password.","url":"https://www.postgresql.org/support/security/CVE-2009-3231/","vector":""},"reviewed_hash":"6a65a7884245936f6adaef8709d290d460e999dfce1ad78734fa7c9a324ed325","source_hash":"965b9e2323feab543f3cbeb74c418c3a5b43cbefc6594d2862ff0d24dcf8e6a2","text":{"locale":"en","title":"If PostgreSQL is configured with LDAP authentication, and your LDAP configuration allows anonymous binds, it is possible for a user to authenticate themselves with an empty password.","description":"","details":null,"format":"plain","provenance":{"fetched_at":"2026-09-26T10:56:06+00:00","path":"compare/security.json","root":"source-data","sha256":"6a65a7884245936f6adaef8709d290d460e999dfce1ad78734fa7c9a324ed325","source_archive_sha256":"8d8ad63581e1d27b3a0f995ded3feb81c265e38b2ac652eb22f022f52c2240ec","source_revision":"004bc292ee31c11f9a41ab007e9d8116bce29a71","source_url":"https://www.postgresql.org/support/security/"},"text_hash":"a9fdac3d6879f83240fac6384fc6e6b2cedfe6050e21148e586bf2406f654342"},"locales":["en"],"fixes":[{"major":"8.2","fixed_version":"8.2.14","introduced":null,"published_date":null,"facts":{"fixed":"8.2.14","introduced":null,"published":null}},{"major":"8.3","fixed_version":"8.3.8","introduced":null,"published_date":null,"facts":{"fixed":"8.3.8","introduced":null,"published":null}}],"legacy":[]}
