Back

HIGH

postgresql: libpq ignores PGREQUIRESSL environment variable

Published May 12, 2017

Description

In PostgreSQL 9.3.x before 9.3.17, 9.4.x before 9.4.12, 9.5.x before 9.5.7, and 9.6.x before 9.6.3, it was found that the PGREQUIRESSL environment variable was no longer enforcing a SSL/TLS connection to a PostgreSQL server. An active Man-in-the-Middle attacker could use this flaw to strip the SSL/TLS protection from a connection between a client and a server.

Affected products

Remediation

Red Hat mitigation

Use PGSSLMODE=require instead of PGREQUIRESSL=1

Metrics

References (13)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner redhat
Published May 12, 2017
Updated Aug 5, 2024
Reserved Apr 5, 2017
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Moderate
Public date May 11, 2017