CVE-2020-13692
Description
PostgreSQL JDBC Driver (aka PgJDBC) before 42.2.13 allows XXE.
Risk Information
Base Score
7.7
MODERATE
Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:L/A:H
EPSS Score
Exploitation Probability
7.355
Associated Vulnerability
| Vulnerability | OS Platform |
|---|---|
| Vulnerabilities CVE-2020-13692 are fixed in PostgreSQL JDBC Driver 42.2.13 | Windows |
| Multiple Vulnerabilities are affected in IBM Security Guardium 11.1 | Windows |
| Multiple Vulnerabilities are affected in IBM Security Guardium 11.2 | Windows |
| Multiple Vulnerabilities are affected in IBM Security Guardium 11.3 | Windows |
| Multiple Vulnerabilities are affected in IBM Security Guardium 11.4 | Windows |
| Multiple Vulnerabilities are affected in IBM Security Guardium 11.0 | Windows |
| (RHSA-2020:3176) postgresql-jdbc security update postgresql-jdbc-42.2.3-3.el8_2.noarch.rpm | Linux |
| (RHSA-2020:3176) postgresql-jdbc security update postgresql-jdbc-javadoc-42.2.3-3.el8_2.noarch.rpm | Linux |
| (RHSA-2020:3284) postgresql-jdbc security update postgresql-jdbc-8.4.704-4.el6_10.noarch.rpm | Linux |
| (RHSA-2020:3285) postgresql-jdbc security update postgresql-jdbc-9.2.1002-8.el7_8.noarch.rpm | Linux |
| (RHSA-2020:3285) postgresql-jdbc security update postgresql-jdbc-javadoc-9.2.1002-8.el7_8.noarch.rpm | Linux |
| Postgresql-jdbc update (ELSA-2020-3176) postgresql-jdbc-42.2.3-3.el8_2.noarch.rpm | Linux |
| Postgresql-jdbc-javadoc update (ELSA-2020-3176) postgresql-jdbc-javadoc-42.2.3-3.el8_2.noarch.rpm | Linux |
| SUSE-SU-2021:0599-1(SUSE Linux Enterprise Server 12-SP5 ) postgresql-jdbc-9.4-3.3.1.noarch.rpm | Linux |
| (CESA-2020:3176) postgresql-jdbc security update postgresql-jdbc-42.2.3-3.el8_2.noarch.rpm | Linux |
| (CESA-2020:3176) postgresql-jdbc security update postgresql-jdbc-javadoc-42.2.3-3.el8_2.noarch.rpm | Linux |
| (CESA-2020:3284) postgresql-jdbc security update postgresql-jdbc-8.4.704-4.el6_10.noarch.rpm | Linux |
| (CESA-2020:3285) postgresql-jdbc security update postgresql-jdbc-9.2.1002-8.el7_8.noarch.rpm | Linux |
| (CESA-2020:3285) postgresql-jdbc security update postgresql-jdbc-javadoc-9.2.1002-8.el7_8.noarch.rpm | Linux |
| postgresql-jdbc security update (RLSA-2020:3176) postgresql-jdbc-42.2.3-3.el8_2.noarch.rpm | Linux |
| postgresql-jdbc security update (RLSA-2020:3176) postgresql-jdbc-javadoc-42.2.3-3.el8_2.noarch.rpm | Linux |
| postgresql-jdbc Security Update (ALAS-2020-1482) postgresql-jdbc-9.2.1002-8.amzn2.noarch.rpm | Linux |
| postgresql-jdbc Security Update (ALAS-2020-1482) postgresql-jdbc-javadoc-9.2.1002-8.amzn2.noarch.rpm | Linux |
| libpgjava security update(DSA-5196-1) libpostgresql-jdbc-java-doc_42.2.5-2+deb10u1_all.deb | Linux |
| libpgjava security update(DSA-5196-1) libpostgresql-jdbc-java-doc_42.2.15-1+deb11u1_all.deb | Linux |
| libpgjava security update(DSA-5196-1) libpostgresql-jdbc-java_42.2.5-2+deb10u1_all.deb | Linux |
| libpgjava security update(DSA-5196-1) libpostgresql-jdbc-java_42.2.15-1+deb11u1_all.deb | Linux |
| Vulnerabilities CVE-2020-13692 are fixed in PostgreSQL JDBC Driver for Linux 42.2.13 | Linux |
| Improper Restriction of XML External Entity Reference Vulnerability (CVE-2020-13692) | NCM |
Patch Details
No records foundReferences
https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234