CVE-2017-7485

MEDIUM

PostgreSQL <9.3.17, 9.4.x <9.4.12, 9.5.x <9.5.7, 9.6.x <9.6.3 - SSRF

Title source: llm
STIX 2.1

Description

In PostgreSQL 9.3.x before 9.3.17, 9.4.x before 9.4.12, 9.5.x before 9.5.7, and 9.6.x before 9.6.3, it was found that the PGREQUIRESSL environment variable was no longer enforcing a SSL/TLS connection to a PostgreSQL server. An active Man-in-the-Middle attacker could use this flaw to strip the SSL/TLS protection from a connection between a client and a server.

References (9)

Core 9
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_sectrack
http://www.securitytracker.com/id/1038476
Third Party Advisory vendor-advisory x_refsource_debian
http://www.debian.org/security/2017/dsa-3851
Vendor Advisory vendor-advisory x_refsource_redhat
https://access.redhat.com/errata/RHSA-2017:2425
Vendor Advisory vendor-advisory x_refsource_redhat
https://access.redhat.com/errata/RHSA-2017:1678
Vendor Advisory vendor-advisory x_refsource_redhat
https://access.redhat.com/errata/RHSA-2017:1677
Vendor Advisory x_refsource_confirm
https://www.postgresql.org/about/news/1746/
Vendor Advisory vendor-advisory x_refsource_redhat
https://access.redhat.com/errata/RHSA-2017:1838
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/98461
Third Party Advisory vendor-advisory x_refsource_gentoo
https://security.gentoo.org/glsa/201710-06

Scores

CVSS v3 5.9
EPSS 0.0089
EPSS Percentile 75.9%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N

Details

CWE
CWE-311 CWE-390
Status published
Products (40)
postgresql/postgresql 9.3
postgresql/postgresql 9.3.1
postgresql/postgresql 9.3.2
postgresql/postgresql 9.3.3
postgresql/postgresql 9.3.4
postgresql/postgresql 9.3.5
postgresql/postgresql 9.3.6
postgresql/postgresql 9.3.7
postgresql/postgresql 9.3.8
postgresql/postgresql 9.3.9
... and 30 more
Published May 12, 2017
Tracked Since Feb 18, 2026