Alpine: java-postgresql-jdbc: security update to 42.2.25-r0

critical Tenable Cloud Security Plugin ID 405030

Description

There are packages installed that are affected by multiple vulnerabilities referenced in the following CVEs:

- PostgreSQL JDBC Driver (aka PgJDBC) before 42.2.13 allows XXE. (CVE-2020-13692)

- pgjdbc is the offical PostgreSQL JDBC Driver. A security hole was found in the jdbc driver for postgresql
database while doing security research. The system using the postgresql library will be attacked when
attacker control the jdbc url or properties. pgjdbc instantiates plugin instances based on class names
provided via `authenticationPluginClassName`, `sslhostnameverifier`, `socketFactory`, `sslfactory`,
`sslpasswordcallback` connection properties. However, the driver did not verify if the class implements
the expected interface before instantiating the class. This can lead to code execution loaded via
arbitrary classes. Users using plugins are advised to upgrade. There are no known workarounds for this
issue. (CVE-2022-21724)

See Also

https://security.alpinelinux.org/vuln/CVE-2020-13692

https://security.alpinelinux.org/vuln/CVE-2022-21724

Plugin Details

Severity: Critical

ID: 405030

Version: Revision 1.31

Type: Local

Published: 10/31/2023

Updated: 7/2/2026

Supported Sensors: Agentless Assessment, Tenable Cloud Security, Tenable Self-Hosted Container Security

Risk Information

VPR

Risk Factor: Medium

Score: 4.9

Percentile: 57.58

CVSS v2

Risk Factor: High

Base Score: 7.5

Temporal Score: 5.9

Vector: CVSS2#AV:N/AC:L/Au:N/C:P/I:P/A:P

CVSS Score Source: CVE-2022-21724

CVSS v3

Risk Factor: Critical

Base Score: 9.8

Temporal Score: 8.8

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Temporal Vector: CVSS:3.0/E:P/RL:O/RC:C

Vulnerability Information

Exploit Available: true

Exploit Ease: Exploits are available

Vulnerability Publication Date: 6/4/2020

Reference Information

CVE: CVE-2020-13692, CVE-2022-21724