42.7.13
13 years ago
2 months ago
Known vulnerabilities in the org.postgresql:postgresql package. This does not include vulnerabilities belonging to this package’s dependencies.
Snyk's AI Trust Platform automatically finds the best upgrade path and integrates with your development workflows. Secure your code at zero cost.
Fix for free| Vulnerability | Vulnerable Version |
|---|---|
org.postgresql:postgresql is a Java JDBC 4.2 (JRE 8+) driver for PostgreSQL database. Affected versions of this package are vulnerable to Incorrect Implementation of Authentication Algorithm in the How to fix Incorrect Implementation of Authentication Algorithm? Upgrade | [,42.7.12) |
org.postgresql:postgresql is a Java JDBC 4.2 (JRE 8+) driver for PostgreSQL database. Affected versions of this package are vulnerable to Allocation of Resources Without Limits or Throttling during the client-side SCRAM-SHA-256 authentication. An attacker can cause excessive CPU consumption by specifying a very large PBKDF2 iteration count during authentication attempts from a malicious server. This can lead to exhaustion of client CPU resources and disruption of connection pools. How to fix Allocation of Resources Without Limits or Throttling? Upgrade | [42.2.0,42.7.11) |