Uploaded image for project: 'CloverDX'
  1. CloverDX
  2. CLO-23209

CVE FIX - Upgrade postgresql to v42.3.3

    XMLWordPrintable

Details

    • Task
    • Status: Closed
    • Critical
    • Resolution: Fixed
    • rel-5-15-0
    • rel-5-15-0
    • None
    • Security Level: Users (General product issues)

    Description

      CVE-2022-21724.pkg:maven/org.postgresql/[email protected] (from postgresql-42.2.13.jar._data_jenkins_.gradle_caches_modules-2_files-2.1_org.postgresql_postgresql_42.2.13_750a4e6dbc753308f50e998920b760b2b5c048ad_postgresql-42.2.13.jar)
      
      Error Message
      
      cvssV3: CRITICAL, score: 9.8 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
      
      Standard Output
      
      pgjdbc is the offical PostgreSQL JDBC Driver. A security hole was found in the jdbc driver for postgresql database while doing security research. The system using the postgresql library will be attacked when attacker control the jdbc url or properties. pgjdbc instantiates plugin instances based on class names provided via `authenticationPluginClassName`, `sslhostnameverifier`, `socketFactory`, `sslfactory`, `sslpasswordcallback` connection properties. However, the driver did not verify if the class implements the expected interface before instantiating the class. This can lead to code execution loaded via arbitrary classes. Users using plugins are advised to upgrade. There are no known workarounds for this issue.
      
      Standard Error
      
      location: /data/jenkins/.gradle/caches/modules-2/files-2.1/org.postgresql/postgresql/42.2.13/750a4e6dbc753308f50e998920b760b2b5c048ad/postgresql-42.2.13.jar
      

      Attachments

        Issue Links

          Activity

            People

              adamekl Lukas Adamek (Inactive)
              pohlp Petr Pohl
              Votes:
              0 Vote for this issue
              Watchers:
              6 Start watching this issue

              Dates

                Created:
                Updated:
                Resolved: