CVE-2025-2291
16.04.2025, 18:16
Password can be used past expiry in PgBouncer due to auth_query not taking into account Postgres its VALID UNTIL value, which allows an attacker to log in with an already expired passwordEnginsight
| Vendor | Product | Version |
|---|---|---|
| pgbouncer | pgbouncer | 𝑥 < 1.24.1 |
| debian | debian_linux | 11.0 |
𝑥
= Vulnerable software versions
Debian Releases
Common Weakness Enumeration