CVE-2025-2291
EUVD-2025-1137916.04.2025, 18:16
Password can be used past expiry in PgBouncer due to auth_query not taking into account Postgres its VALID UNTIL value, which allows an attacker to log in with an already expired passwordEnginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| pgbouncer | pgbouncer | 𝑥 < 1.24.1 |
| debian | debian_linux | 11.0 |
𝑥
= Vulnerable software versions
Debian Releases
Common Weakness Enumeration