High severityNVD Advisory· Published Apr 27, 2021· Updated Aug 3, 2024
CVE-2021-31671
CVE-2021-31671
Description
pgsync before 0.6.7 is affected by Information Disclosure of sensitive information. Syncing the schema with the --schema-first and --schema-only options is mishandled. For example, the sslmode connection parameter may be lost, which means that SSL would not be used.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
pgsyncRubyGems | < 0.6.7 | 0.6.7 |
Affected products
2- pgsync/pgsyncdescription
Patches
Vulnerability mechanics
References
6- github.com/advisories/GHSA-72rj-36qc-47g7ghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2021-31671ghsaADVISORY
- github.com/ankane/pgsync/blob/master/CHANGELOG.mdghsaWEB
- github.com/ankane/pgsync/commit/05cd18f5fc09407e4b544f2c12f819cabc50c40eghsaWEB
- github.com/ankane/pgsync/issues/121ghsax_refsource_MISCWEB
- github.com/rubysec/ruby-advisory-db/blob/master/gems/pgsync/CVE-2021-31671.ymlghsaWEB
News mentions
0No linked articles in our index yet.