Description
pgsync before 0.6.7 is affected by Information Disclosure of sensitive information. Syncing the schema with the --schema-first and --schema-only options is mishandled. For example, the sslmode connection parameter may be lost, which means that SSL would not be used.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2021-0780 | pgsync before 0.6.7 is affected by Information Disclosure of sensitive information. Syncing the schema with the --schema-first and --schema-only options is mishandled. For example, the sslmode connection parameter may be lost, which means that SSL would not be used. |
Github GHSA |
GHSA-72rj-36qc-47g7 | Pgsync Contains Cleartext Transmission of Sensitive Information |
References
| Link | Providers |
|---|---|
| https://github.com/ankane/pgsync/issues/121 |
|
History
No history.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-03T23:03:33.788Z
Reserved: 2021-04-23T00:00:00.000Z
Link: CVE-2021-31671
No data.
Status : Modified
Published: 2021-04-27T03:15:07.647
Modified: 2024-11-21T06:06:06.230
Link: CVE-2021-31671
No data.
OpenCVE Enrichment
No data.
Weaknesses
-
CWE-319
Cleartext Transmission of Sensitive Information
EUVD
Github GHSA