6.8
CVSSv2

CVE-2020-13692

Published: 04/06/2020 Updated: 07/11/2023
CVSS v2 Base Score: 6.8 | Impact Score: 6.4 | Exploitability Score: 8.6
CVSS v3 Base Score: 7.7 | Impact Score: 5.5 | Exploitability Score: 2.2
VMScore: 605
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

PostgreSQL JDBC Driver (aka PgJDBC) prior to 42.2.13 allows XXE.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

postgresql postgresql jdbc driver

quarkus quarkus

netapp steelstore cloud integrated storage -

fedoraproject fedora 32

debian debian linux 10.0

debian debian linux 11.0

Vendor Advisories

Debian Bug report logs - #962828 libpgjava: CVE-2020-13692 Package: src:libpgjava; Maintainer for src:libpgjava is Debian Java Maintainers <pkg-java-maintainers@listsaliothdebianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Sun, 14 Jun 2020 19:33:02 UTC Severity: important Tags: security, upstr ...
Several security vulnerabilities have been found in libpgjava, the official PostgreSQL JDBC Driver CVE-2020-13692 An XML External Entity (XXE) weakness was found in PostgreSQL JDBC CVE-2022-21724 The JDBC driver did not verify if certain classes implemented the expected interface before instantiating the class This can lead to code ...
PostgreSQL JDBC Driver (aka PgJDBC) before 42213 allows XXE A flaw was found in PostgreSQL JDBC in versions prior to 42213 An XML External Entity (XXE) weakness was found in PostgreSQL JDBC The highest threat from this vulnerability is to data confidentiality and system availability (CVE-2020-13692) ...
A flaw was found in PostgreSQL JDBC in versions prior to 42213 An XML External Entity (XXE) weakness was found in PostgreSQL JDBC The highest threat from this vulnerability is to data confidentiality and system availability (CVE-2020-13692) ...
Synopsis Important: postgresql-jdbc security update Type/Severity Security Advisory: Important Topic An update for postgresql-jdbc is now available for Red Hat Enterprise Linux 81 Extended Update SupportRed Hat Product Security has rated this update as having a security impact of Important A Common Vulne ...
Synopsis Important: Red Hat Process Automation Manager 781 Security Update Type/Severity Security Advisory: Important Topic An update is now available for Red Hat Process Automation ManagerRed Hat Product Security has rated this update as having a security impact of Moderate A Common Vulnerability Scori ...
Synopsis Moderate: AMQ Online 152 release and security update Type/Severity Security Advisory: Moderate Topic An update of the Red Hat OpenShift Container Platform 311 and 44/45 container images is now available for Red Hat AMQ OnlineRed Hat Product Security has rated this update as having a security ...
Synopsis Important: postgresql-jdbc security update Type/Severity Security Advisory: Important Topic An update for postgresql-jdbc is now available for Red Hat Enterprise Linux 80 Update Services for SAP SolutionsRed Hat Product Security has rated this update as having a security impact of Important A Co ...
Synopsis Important: postgresql-jdbc security update Type/Severity Security Advisory: Important Topic An update for postgresql-jdbc is now available for Red Hat Enterprise Linux 8Red Hat Product Security has rated this update as having a security impact of Important A Common Vulnerability Scoring System (C ...
Synopsis Important: Red Hat Integration Debezium 113 security update Type/Severity Security Advisory: Important Topic An update for Debezium PostgreSQL connector is now available for Red Hat IntegrationRed Hat Product Security has rated this update as having a security impact of Important A Common Vulne ...
Synopsis Important: Red Hat Decision Manager 781 Security Update Type/Severity Security Advisory: Important Topic An update is now available for Red Hat Decision ManagerRed Hat Product Security has rated this update as having a security impact of Moderate A Common Vulnerability Scoring System (CVSS) bas ...
Synopsis Important: Red Hat Integration Tech-Preview 2 Camel K security update Type/Severity Security Advisory: Important Topic An update to the Camel K operator image for Red Hat Integration tech-preview is now available The purpose of this text-only errata is to inform you about the security issues fixed ...
Synopsis Important: Red Hat build of Quarkus 134 SP1 release and security update Type/Severity Security Advisory: Important Topic An update is now available for Red Hat build of QuarkusRed Hat Product Security has rated this update as having a security impact of Important A Common Vulnerability Scoring ...
Synopsis Important: postgresql-jdbc security update Type/Severity Security Advisory: Important Topic An update for postgresql-jdbc is now available for Red Hat Enterprise Linux 6Red Hat Product Security has rated this update as having a security impact of Important A Common Vulnerability Scoring System (C ...
Synopsis Important: postgresql-jdbc security update Type/Severity Security Advisory: Important Topic An update for postgresql-jdbc is now available for Red Hat Enterprise Linux 7Red Hat Product Security has rated this update as having a security impact of Important A Common Vulnerability Scoring System (C ...
Synopsis Important: Red Hat Fuse 780 release and security update Type/Severity Security Advisory: Important Topic A minor version update (from 77 to 78) is now available for Red Hat Fuse The purpose of this text-only errata is to inform you about the security issues fixed in this releaseRed Hat Produc ...

Github Repositories

Java Software Security Course Work and Projects

CS-305 Java Software Security Course Work and Projects Alexandrea Teigeler 2022 #--------------------------------------------------------------------------------------------------------------# Briefly summarize your client, Artemis Financial, and their software requirements #--------------------------------------------------------------------------------------------------------

References

CWE-611https://jdbc.postgresql.org/documentation/changelog.html#version_42.2.13https://github.com/pgjdbc/pgjdbc/commit/14b62aca4764d496813f55a43d050b017e01eb65https://security.netapp.com/advisory/ntap-20200619-0005/https://www.debian.org/security/2022/dsa-5196https://lists.apache.org/thread.html/r00bcc6b2da972e0d6332a4ebc7807e17305d8b8e7fb2ae63d2a3cbfb%40%3Ccommits.camel.apache.org%3Ehttps://lists.apache.org/thread.html/r7f6d019839df17646ffd0046a99146cacf40492a6c92078f65fd32e0%40%3Ccommits.camel.apache.org%3Ehttps://lists.apache.org/thread.html/r1aae77706aab7d89b4fe19be468fc3c73e9cc84ff79cc2c3bd07c05a%40%3Ccommits.camel.apache.org%3Ehttps://lists.apache.org/thread.html/r0478a1aa9ae0dbd79d8f7b38d0d93fa933ac232e2b430b6f31a103c0%40%3Ccommits.camel.apache.org%3Ehttps://lists.apache.org/thread.html/r01ae1b3d981cf2e563e9b5b0a6ea54fb3cac8e9a0512ee5269e3420e%40%3Ccommits.camel.apache.org%3Ehttps://lists.apache.org/thread.html/r631f967db6260d6178740a3314a35d9421facd8212e62320275fa78e%40%3Ccommits.camel.apache.org%3Ehttps://lists.apache.org/thread.html/rfe363bf3a46d440ad57fd05c0e313025c7218364bbdc5fd8622ea7ae%40%3Ccommits.camel.apache.org%3Ehttps://lists.apache.org/thread.html/r4bdea189c9991aae7a929d28f575ec46e49ed3d68fa5235825f38a4f%40%3Cnotifications.netbeans.apache.org%3Ehttps://lists.apache.org/thread.html/rb89f92aba44f524d5c270e0c44ca7aec4704691c37fe106cf73ec977%40%3Cnotifications.netbeans.apache.org%3Ehttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/DCCAPM6FSNOC272DLSNQ6YHXS3OMHGJC/https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=962828https://nvd.nist.govhttps://github.com/Teiga-artzee/CS-305https://www.debian.org/security/2022/dsa-5196