PT-2026-102914 · Pgpool-Ii · Pgpool-Ii
CVSS v3.1
6.5
Medium
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Pgpool-II versions prior to 4.7.3
Description
An improper certificate validation issue exists that may allow an unauthenticated attacker to bypass client certificate authentication. Approximately 101 instances have been identified globally.
Recommendations
Update to version 4.7.3 or later.
Fix
RCE
Improper Certificate Validation
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Pgpool-Ii