Password can be used past expiry in PgBouncer due to auth_query not taking into account Postgres its VALID UNTIL value, which allows an attacker to log in with an already expired password
The product uses a cryptographic key or password past its expiration date, which diminishes its safety significantly by increasing the timing window for cracking attacks against that key.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Pgbouncer | Ubuntu | upstream | * |