VDB
Sign up
HIGH8.2

GHSA-hq9p-pm7w-8p54

pgjdbc Client Allows Fallback to Insecure Authentication Despite channelBinding=require Configuration

Quick fix

GHSA-hq9p-pm7w-8p54 — org.postgresql:postgresql: upgrade to the fixed version with the command below.

# pom.xml: bump <version>42.7.7</version> for org.postgresql:postgresql

Details

### Impact When the PostgreSQL JDBC driver is configured with channel binding set to `required` (default value is `prefer`), the driver would incorrectly allow connections to proceed with authentication methods that do not support channel binding (such as password, MD5, GSS, or SSPI authentication). This could allow a man-in-the-middle attacker to intercept connections that users believed were protected by channel binding requirements.

### Patches TBD

### Workarounds

Configure `sslMode=verify-full` to prevent MITM attacks.

### References

* https://www.postgresql.org/docs/current/sasl-authentication.html#SASL-SCRAM-SHA-256 * https://datatracker.ietf.org/doc/html/rfc7677 * https://datatracker.ietf.org/doc/html/rfc5802

Are you affected?

Enter the version of the package you're using.

Affected packages

Maven/org.postgresql:postgresql
Introduced in: 42.7.4Fixed in: 42.7.7
Fix# pom.xml: bump <version>42.7.7</version> for org.postgresql:postgresql

References