Medium severity6.5NVD Advisory· Published Jan 30, 2023· Updated Jun 17, 2026
CVE-2023-22332
CVE-2023-22332
Description
Information disclosure vulnerability exists in Pgpool-II 4.4.0 to 4.4.1 (4.4 series), 4.3.0 to 4.3.4 (4.3 series), 4.2.0 to 4.2.11 (4.2 series), 4.1.0 to 4.1.14 (4.1 series), 4.0.0 to 4.0.21 (4.0 series), All versions of 3.7 series, All versions of 3.6 series, All versions of 3.5 series, All versions of 3.4 series, and All versions of 3.3 series. A specific database user's authentication information may be obtained by another database user. As a result, the information stored in the database may be altered and/or database may be suspended by a remote attacker who successfully logged in the product with the obtained credentials.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
34.4.0 to 4.4.1, 4.3.0 to 4.3.4, 4.2.0 to 4.2.11, 4.1.0 to 4.1.14, 4.0.0 to 4.0.21, All versions of 3.7, 3.6, 3.5, 3.4, 3.3 series+ 2 more
- (no CPE)range: 4.4.0 to 4.4.1, 4.3.0 to 4.3.4, 4.2.0 to 4.2.11, 4.1.0 to 4.1.14, 4.0.0 to 4.0.21, All versions of 3.7, 3.6, 3.5, 3.4, 3.3 series
- (no CPE)range: 4.4.0 to 4.4.1 (4.4 series), 4.3.0 to 4.3.4 (4.3 series), 4.2.0 to 4.2.11 (4.2 series), 4.1.0 to 4.1.14 (4.1 series), 4.0.0 to 4.0.21 (4.0 series), All versions of 3.7 series, All versions of 3.6 series, All versions of 3.5 series, All versions of 3.4 series, and All versions of 3.3 series
- cpe:2.3:a:pgpool:pgpool-ii:*:*:*:*:*:*:*:*range: >=3.3.0,<=3.7.12
Patches
Vulnerability mechanics
References
3- jvn.jp/en/jp/JVN72418815/nvdThird Party Advisory
- www.pgpool.net/mediawiki/index.php/Main_PagenvdVendor Advisory
- lists.debian.org/debian-lts-announce/2024/12/msg00015.htmlnvd
News mentions
0No linked articles in our index yet.