VDB
DEBIAN-CVE-2018-10936
DEBIAN-CVE-2018-10936
PUBLISHED
CVSS 8.100000381469727 HIGH
A weakness was found in postgresql-jdbc before version 42.2.5. It was possible to provide an SSL Factory and not check the host name if a host name verifier was not provided to the driver. This could lead to a condition where a man-in-the-middle attacker could masquerade as a trusted server by providing a certificate for the wrong host, as long as it was signed by a trusted CA.
Risk Scores
CVSS v3.0
8.100000381469727
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Debian:11 | libpgjava | 0, 0, 0 |
| Debian:14 | libpgjava | 0, 0, 0 |
| Debian:12 | libpgjava | 0, 0, 0 |
| Debian:13 | libpgjava | 0, 0, 0 |
Exploit Intelligence
- tafamace/CVE-2018-10936 (github-poc-repo)
- tafamace/CVE-2018-10936 (github-poc)
- druid-612f0710.json (github-poc)
Timeline
- Aug 30, 2018 CVE Published
- Apr 28, 2026 CVE Updated