First published: Thu Jun 04 2020(Updated: )
PostgreSQL JDBC Driver could allow a remote authenticated attacker to obtain sensitive information, caused by an XML external entity (XXE) error when processing XML data. By sending specially crafted XML data, a remote attacker could exploit this vulnerability to obtain sensitive information.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
redhat/postgresql-jdbc | <0:8.4.704-4.el6_10 | 0:8.4.704-4.el6_10 |
redhat/postgresql-jdbc | <0:9.2.1002-8.el7_8 | 0:9.2.1002-8.el7_8 |
redhat/postgresql-jdbc | <0:42.2.3-3.el8_2 | 0:42.2.3-3.el8_2 |
redhat/postgresql-jdbc | <0:42.2.3-3.el8_0 | 0:42.2.3-3.el8_0 |
redhat/postgresql-jdbc | <0:42.2.3-3.el8_1 | 0:42.2.3-3.el8_1 |
debian/libpgjava | 42.2.5-2+deb10u1 42.2.5-2+deb10u3 42.2.15-1+deb11u1 42.5.4-1 42.6.0-2 | |
Postgresql Postgresql Jdbc Driver | <42.2.13 | |
Quarkus Quarkus | <=1.5.2 | |
Netapp Steelstore Cloud Integrated Storage | ||
Fedoraproject Fedora | =32 | |
Debian Debian Linux | =10.0 | |
Debian Debian Linux | =11.0 | |
IBM ISAM | <=9.0.7 | |
IBM Security Verify Access | <=10.0.0 | |
redhat/postgresql-jdbc | <42.2.13 | 42.2.13 |
maven/org.postgresql:postgresql | >=9.4.1212.jre6<42.2.13 | 42.2.13 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Appears in the following advisories)
CVE-2020-13692 is a vulnerability in the PostgreSQL JDBC Driver.
CVE-2020-13692 allows a remote attacker to obtain sensitive information by exploiting an XML external entity (XXE) error in the driver.
CVE-2020-13692 has a severity value of 7.7, which is classified as high severity.
PostgreSQL JDBC Driver versions before 42.2.13 are affected by CVE-2020-13692.
To fix CVE-2020-13692, you should update your PostgreSQL JDBC Driver to version 42.2.13 or higher.