CVE Vulnerabilities

CVE-2025-2291

Use of a Key Past its Expiration Date

Published: Apr 16, 2025 | Modified: Apr 17, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM

Password can be used past expiry in PgBouncer due to auth_query not taking into account Postgres its VALID UNTIL value, which allows an attacker to log in with an already expired password

Weakness

The product uses a cryptographic key or password past its expiration date, which diminishes its safety significantly by increasing the timing window for cracking attacks against that key.

Affected Software

Name Vendor Start Version End Version
Pgbouncer Ubuntu upstream *

Potential Mitigations

References