Impact
Pgpool‑II implements an authentication algorithm incorrectly, which may allow an unauthenticated attacker to promote an arbitrary watchdog node to the leader node. The likely effect of this promotion is that the attacker could gain elevated control over database traffic routing, potentially redirecting traffic or disrupting service. Based on the description, it is inferred that such a change might compromise the integrity and availability of the database cluster.
Affected Systems
The flaw affects Pgpool II from the Pgpool Global Development Group. No specific version range is provided, so all installations of Pgpool‑II should be treated as affected until a vendor releases a patch.
Risk and Exploitability
The CVSS score of 6.9 indicates moderate severity. EPSS data is not available and the vulnerability is not listed in the CISA KEV catalog, so no known active exploitation is documented. The likely attack vector is over the network to the Pgpool‑II service, requiring no authentication. This makes the threat realistic in environments where the service is exposed.
OpenCVE Enrichment