« Volver al listado

Pgpool

Pgpool-ii: vulnerabilidades y CVE

Pgpool-ii tiene 10 vulnerabilidades publicadas, 7 de ellas en los últimos 12 meses. 1 son críticas y 0 figuran en el catálogo de explotación activa de CISA.

CVE10
Últimos 12 meses7
Críticas1
Explotadas activamente0

Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología

Últimas vulnerabilidades

CVESeveridadEPSSExplotación activaPublicadaDescripción
CVE-2026-92873Media (6.9)0.31%—30 sept 2026
Pgpool-II contains an incorrect implementation of an authentication algorithm, which may allow an unauthenticated attacker to promote an arbitrary watchdog node to the leader node.
CVE-2026-92872Media (5.3)0.18%—30 sept 2026
Pgpool-II inserts sensitive information into log file, which may allow an authenticated attacker to obtain the cluster information.
CVE-2026-92871Alta (8.7)0.29%—30 sept 2026
A NULL pointer dereference vulnerability exists in Pgpool-II, which may allow an unauthenticated attacker to cause abnormal termination of the watchdog process.
CVE-2026-92870Alta (8.7)0.32%—30 sept 2026
A stack-based buffer overflow vulnerability exists in Pgpool-II, which may allow an unauthenticated attacker to cause abnormal process termination.
CVE-2026-92869Alta (7.1)0.25%—30 sept 2026
An out-of-bounds write vulnerability exists in Pgpool-II, which may allow an authenticated attacker to cause abnormal process termination.
CVE-2026-92868Media (6.9)0.15%—30 sept 2026
An improper certificate validation vulnerability exists in Pgpool-II, which may allow an unauthenticated attacker to bypass client certificate authentication.
CVE-2026-92867Alta (8.7)0.34%—30 sept 2026
An out-of-bounds write vulnerability exists in Pgpool-II , which may allow an authenticated attacker to cause abnormal process termination or arbitrary code execution.
CVE-2025-46801Crítica (9.3)0.91%—19 may 2025
Pgpool-II provided by PgPool Global Development Group contains an authentication bypass by primary weakness vulnerability. if the vulnerability is exploited, an attacker may be able to log in to the system as an…
CVE-2024-45624Alta (7.5)0.53%—12 sept 2024
Exposure of sensitive information due to incompatible policies issue exists in Pgpool-II. If a database user accesses a query cache, table data unauthorized for the user may be retrieved.
CVE-2023-22332Media (6.5)0.70%—30 ene 2023
Information disclosure vulnerability exists in Pgpool-II 4.4.0 to 4.4.1 (4.4 series), 4.3.0 to 4.3.4 (4.3 series), 4.2.0 to 4.2.11 (4.2 series), 4.1.0 to 4.1.14 (4.1 series), 4.0.0 to 4.0.21 (4.0 series), All versions…

🎯 Cómo se explota (técnicas ATT&CK)

  1. T1190 Exploit Public-Facing Application5
  2. T1210 Exploitation of Remote Services3
  3. T1499.004 Application or System Exploitation3
  4. T1059 Command and Scripting Interpreter1
  5. T1078 Valid Accounts1
  6. T1098.001 Additional Cloud Credentials1

Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.

Otros productos de Pgpool