PgBouncer 1.16.0

CPE Details

PgBouncer 1.16.0
1.16.0
2021-11-26
12h54 +00:00
2021-11-26
12h56 +00:00
Alerte pour un CPE
Stay informed of any changes for a specific CPE.
Notifications manage

CPE Name: cpe:2.3:a:pgbouncer:pgbouncer:1.16.0:*:*:*:*:*:*:*

Informations

Vendor

pgbouncer

Product

pgbouncer

Version

1.16.0

Related CVE

Open and find in CVE List

CVE ID Published Description Score Severity
CVE-2021-3672 2021-11-22 23h00 +00:00 A flaw was found in c-ares library, where a missing input validation check of host names returned by DNS (Domain Name Servers) can lead to output of wrong hostnames which might potentially lead to Domain Hijacking. The highest threat from this vulnerability is to confidentiality and integrity as well as system availability.
5.6
Medium
CVE-2021-3935 2021-11-22 14h59 +00:00 When PgBouncer is configured to use "cert" authentication, a man-in-the-middle attacker can inject arbitrary SQL queries when a connection is first established, despite the use of TLS certificate verification and encryption. This flaw affects PgBouncer versions prior to 1.16.1.
8.1
High