Password can be used past expiry in PgBouncer due to auth_query not taking into account Postgres its VALID UNTIL value, which allows an attacker to log in with an already expired password
References
Configurations
No configuration.
History
03 Nov 2025, 20:18
| Type | Values Removed | Values Added |
|---|---|---|
| Summary |
|
|
| References |
|
16 Apr 2025, 18:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2025-04-16 18:16
Updated : 2025-11-03 20:18
NVD link : CVE-2025-2291
Mitre link : CVE-2025-2291
CVE.ORG link : CVE-2025-2291
JSON object : View
Products Affected
No product.
CWE
CWE-324
Use of a Key Past its Expiration Date
