CVE-2020-13692

HIGH

Postgresql Jdbc Driver < 42.2.13 - XXE

Title source: rule
STIX 2.1

Description

PostgreSQL JDBC Driver (aka PgJDBC) before 42.2.13 allows XXE.

References (14)

Core 14
Core References
Release Notes, Vendor Advisory x_refsource_confirm
https://jdbc.postgresql.org/documentation/changelog.html#version_42.2.13
Third Party Advisory x_refsource_confirm
https://security.netapp.com/advisory/ntap-20200619-0005/
Third Party Advisory vendor-advisory x_refsource_debian
https://www.debian.org/security/2022/dsa-5196

Scores

CVSS v3 7.7
EPSS 0.0780
EPSS Percentile 92.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:L/A:H

Details

CWE
CWE-611
Status published
Products (7)
debian/debian_linux 10.0
debian/debian_linux 11.0
fedoraproject/fedora 32
netapp/steelstore_cloud_integrated_storage
org.postgresql/postgresql 9.4.1212.jre6 - 42.2.13Maven
postgresql/postgresql_jdbc_driver < 42.2.13
quarkus/quarkus < 1.5.2
Published Jun 04, 2020
Tracked Since Feb 18, 2026