Impact
Pgpool-II logs sensitive cluster information, allowing an authenticated attacker to read secrets that should remain confidential. This results in a breach of confidentiality and is described as a Confidentiality Impact under CWE-532.
Affected Systems
The vulnerability is found in Pgpool-II from Pgpool Global Development Group. No specific version ranges are listed, so all current releases that lack a vendor patch may be affected.
Risk and Exploitability
The CVSS score of 5.3 indicates a moderate severity and the EPSS score is not available. Because the attacker needs authenticated access it is less likely to be widely exploited and the vulnerability is not listed in CISA's KEV catalog. The most likely exploitation path involves a legitimate user triggering verbose logging and then reviewing the logs to obtain cluster data.
OpenCVE Enrichment