ALPINE-CVE-2017-7546 PUBLISHED CVSS 9.800000190734863 CRITICAL

PostgreSQL versions before 9.2.22, 9.3.18, 9.4.13, 9.5.8 and 9.6.4 are vulnerable to incorrect authentication flaw allowing remote attackers to gain access to database accounts with an empty password.

Risk Scores

CVSS v3.0
9.800000190734863
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Affected Products

VendorProductVersions
Alpine:v3.13postgresql8.4.0-r1, 9.0.2-r0, 9.5.0-r0
Alpine:v3.19postgresql150, 0, 0
Alpine:v3.14postgresql9.1.4-r0, 9.6.3-r0, 9.6.2-r4
Alpine:v3.17postgresql148.4.0-r2, 9.5.4-r0, 9.6.0-r0
Alpine:v3.18postgresql149.1.2-r0, 8.3.5-r0, 8.3.7-r0
Alpine:v3.16postgresql149.3.3-r0, 9.1.0-r0, 9.3.0-r0
Alpine:v3.10postgresql9.1.0-r1, 9.6.3-r0, 9.6.2-r4
Alpine:v3.4postgresql9.4.1-r1, 9.5.7-r0, 9.5.6-r0
Alpine:v3.7postgresql9.1.2-r1, 9.1.3-r0, 9.4.5-r0
Alpine:v3.9postgresql9.6.3-r0, 8.4.0-r2, 9.1.1-r2
Alpine:v3.12postgresql9.3.3-r1, 0, 8.3.7-r0
Alpine:v3.18postgresql150, 0, 0
Alpine:v3.6postgresql9.1.0-r0, 9.0.4-r0, 9.0.3-r1
Alpine:v3.3postgresql9.4.6-r0, 8.4.2-r0, 0
Alpine:v3.15postgresql148.4.1-r0, 8.4.0-r1, 8.4.0-r0
Alpine:v3.20postgresql150, 0, 0
Alpine:v3.8postgresql9.6.2-r2, 8.3.5-r0, 8.3.7-r0
Alpine:v3.11postgresql9.1.1-r2, 9.1.0-r1, 9.1.0-r0
Alpine:v3.5postgresql9.5.3-r0, 9.1.1-r0, 9.1.0-r1
Alpine:v3.17postgresql150, 0, 0

Timeline

References

Open in Interactive Console →