PgBouncer
cpe:2.3:a:pgbouncer:pgbouncer:*:*:*:*:*:*:*, +1 more
- < 1.25.2
An authorization bypass vulnerability has been identified in PgBouncer versions prior to 1.25.2, allowing all users with access to the administration console to execute the KILL_CLIENT command. This command, which terminates client connections, should only be available to users specified in the admin_users parameter. The vulnerability arises from the application's failure to properly restrict access to the command based on user privileges.
Exploitation of this vulnerability allows unauthorized users to terminate client connections, potentially disrupting active database operations or user activities.
Users can upgrade to PgBouncer version 1.25.2 or later, where this vulnerability has been fixed.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.