↑↓ select↵ open⌫ change scopeOpen full search

PG.CENTER connects PostgreSQL documentation, reference, and ecosystem knowledge. Maintained by Pigsty.

CVE-2020-25694

Many PostgreSQL-provided client applications have options that create additional database connections. Some of those applications reuse only the basic connection parameters (e.g. host , user , port ), dropping others. If this drops a security-relevant parameter (e.g. channel_binding , sslmode , requirepeer , gssencmode ), the attacker has an opportunity to complete a MITM attack or observe cleartext transmission. Affected applications are clusterdb , pg_dump , pg_restore , psql , reindexdb , and vacuumdb . The vulnerability arises only if one invokes an affected client application with a connection string containing a security-relevant parameter. This also fixes how the \connect command of psql reuses connection parameters, i.e. all non-overridden parameters from a previous connection string now re-used. The PostgreSQL project thanks Peter Eisentraut for reporting this problem.

Version Information

Affected branchIntroducedFixed InFix Published
10—10.152020-11-12
11—11.102020-11-12
12—12.52020-11-12
13—13.12020-11-12
9.5—9.5.242020-11-12
9.6—9.6.202020-11-12

CVSS 3.0

Overall Score8.1
Componentclient
VectorAV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

First published: 2020-11-12

Original security advisory · JSON · All advisories