patroni@0.76 vulnerabilities

PostgreSQL High-Available orchestrator and CLI

  • latest version

    4.0.6

  • latest non vulnerable version

  • first published

    9 years ago

  • latest version published

    2 months ago

  • licenses detected

  • Direct Vulnerabilities

    Known vulnerabilities in the patroni package. This does not include vulnerabilities belonging to this package’s dependencies.

    How to fix?

    Automatically find and fix vulnerabilities affecting your projects. Snyk scans for vulnerabilities and provides fixes for free.

    Fix for free
    VulnerabilityVulnerable Version
    • M
    Timing Attack

    patroni is a PostgreSQL High-Available orchestrator and CLI.

    Affected versions of this package are vulnerable to Timing Attack via auth key comparison, as 'hmac.compare_digest()' is used instead of '==' for performing the REST API authentication.

    How to fix Timing Attack?

    Upgrade patroni to version 2.0.2 or higher.

    [0,2.0.2)