BUG #16580: PostgreSQL PassTheHash Protocol Design Weakness Detected - vulnerability

From: PG Bug reporting form <noreply(at)postgresql(dot)org>
To: pgsql-bugs(at)lists(dot)postgresql(dot)org
Cc: kranthi(dot)k(dot)bhavanam(at)wellsfargo(dot)com
Subject: BUG #16580: PostgreSQL PassTheHash Protocol Design Weakness Detected - vulnerability
Date: 2020-08-12 20:41:57
Message-ID: 16580-850b0f6abe4fa059@postgresql.org
Views: Raw Message | Whole Thread | Download mbox | Resend email
Thread:
Lists: pgsql-bugs

The following bug has been logged on the website:

Bug reference: 16580
Logged by: kranthi bhavanam
Email address: kranthi(dot)k(dot)bhavanam(at)wellsfargo(dot)com
PostgreSQL version: 10.10
Operating system: RHEL
Description:

PostgreSQL PassTheHash Protocol Design Weakness Detected - this is the
vulnerability detected by our internal scan tool 'qualys'.
Could you please help us understand and remediate the solution for this
vulnerability.

We have 4 environments in total and only 1 env has postgres and other 3 have
MySQL. Why do we see this vulnerability in all 4 environments, even in the
env's where postgres isn't there. Please advise.

Responses

Browse pgsql-bugs by date

  From Date Subject
Next Message Stephen Frost 2020-08-12 20:54:21 Re: BUG #16580: PostgreSQL PassTheHash Protocol Design Weakness Detected - vulnerability
Previous Message Andres Freund 2020-08-12 16:27:18 Re: posgres 12 bug (partitioned table)