{
  "threat_severity" : "Important",
  "public_date" : "2025-06-11T14:32:39Z",
  "bugzilla" : {
    "description" : "pgjdbc: pgjdbc insecure authentication in channel binding",
    "id" : "2372307",
    "url" : "https://bugzilla.redhat.com/show_bug.cgi?id=2372307"
  },
  "cvss3" : {
    "cvss3_base_score" : "8.2",
    "cvss3_scoring_vector" : "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N",
    "status" : "verified"
  },
  "cwe" : "CWE-287",
  "details" : [ "pgjdbc is an open source postgresql JDBC Driver. From 42.7.4 and until 42.7.7, when the PostgreSQL JDBC driver is configured with channel binding set to required (default value is prefer), the driver would incorrectly allow connections to proceed with authentication methods that do not support channel binding (such as password, MD5, GSS, or SSPI authentication). This could allow a man-in-the-middle attacker to intercept connections that users believed were protected by channel binding requirements. This vulnerability is fixed in 42.7.7.", "A connection handling flaw was found in the pgjdbc connection driver in configurations that require channel binding. Connections created with authentication methods that should not allow channel binding permit connections to use channel binding. This flaw allows attackers to position themselves in the middle of a connection and intercept the connection." ],
  "affected_release" : [ {
    "product_name" : "Cryostat 4 on RHEL 9",
    "release_date" : "2025-07-03T00:00:00Z",
    "advisory" : "RHSA-2025:10323",
    "cpe" : "cpe:/a:redhat:cryostat:4::el9",
    "package" : "cryostat/cryostat-agent-init-rhel9:0.5.1-2"
  }, {
    "product_name" : "Cryostat 4 on RHEL 9",
    "release_date" : "2025-07-03T00:00:00Z",
    "advisory" : "RHSA-2025:10323",
    "cpe" : "cpe:/a:redhat:cryostat:4::el9",
    "package" : "cryostat/cryostat-db-rhel9:4.0.1-5"
  }, {
    "product_name" : "Cryostat 4 on RHEL 9",
    "release_date" : "2025-07-03T00:00:00Z",
    "advisory" : "RHSA-2025:10323",
    "cpe" : "cpe:/a:redhat:cryostat:4::el9",
    "package" : "cryostat/cryostat-grafana-dashboard-rhel9:4.0.1-4"
  }, {
    "product_name" : "Cryostat 4 on RHEL 9",
    "release_date" : "2025-07-03T00:00:00Z",
    "advisory" : "RHSA-2025:10323",
    "cpe" : "cpe:/a:redhat:cryostat:4::el9",
    "package" : "cryostat/cryostat-openshift-console-plugin-rhel9:4.0.1-3"
  }, {
    "product_name" : "Cryostat 4 on RHEL 9",
    "release_date" : "2025-07-03T00:00:00Z",
    "advisory" : "RHSA-2025:10323",
    "cpe" : "cpe:/a:redhat:cryostat:4::el9",
    "package" : "cryostat/cryostat-operator-bundle:4.0.1-2"
  }, {
    "product_name" : "Cryostat 4 on RHEL 9",
    "release_date" : "2025-07-03T00:00:00Z",
    "advisory" : "RHSA-2025:10323",
    "cpe" : "cpe:/a:redhat:cryostat:4::el9",
    "package" : "cryostat/cryostat-ose-oauth-proxy-rhel9:4.0.1-5"
  }, {
    "product_name" : "Cryostat 4 on RHEL 9",
    "release_date" : "2025-07-03T00:00:00Z",
    "advisory" : "RHSA-2025:10323",
    "cpe" : "cpe:/a:redhat:cryostat:4::el9",
    "package" : "cryostat/cryostat-reports-rhel9:4.0.1-3"
  }, {
    "product_name" : "Cryostat 4 on RHEL 9",
    "release_date" : "2025-07-03T00:00:00Z",
    "advisory" : "RHSA-2025:10323",
    "cpe" : "cpe:/a:redhat:cryostat:4::el9",
    "package" : "cryostat/cryostat-rhel9:4.0.1-3"
  }, {
    "product_name" : "Cryostat 4 on RHEL 9",
    "release_date" : "2025-07-03T00:00:00Z",
    "advisory" : "RHSA-2025:10323",
    "cpe" : "cpe:/a:redhat:cryostat:4::el9",
    "package" : "cryostat/cryostat-rhel9-operator:4.0.1-5"
  }, {
    "product_name" : "Cryostat 4 on RHEL 9",
    "release_date" : "2025-07-03T00:00:00Z",
    "advisory" : "RHSA-2025:10323",
    "cpe" : "cpe:/a:redhat:cryostat:4::el9",
    "package" : "cryostat/cryostat-storage-rhel9:4.0.1-5"
  }, {
    "product_name" : "Cryostat 4 on RHEL 9",
    "release_date" : "2025-07-03T00:00:00Z",
    "advisory" : "RHSA-2025:10323",
    "cpe" : "cpe:/a:redhat:cryostat:4::el9",
    "package" : "cryostat/jfr-datasource-rhel9:4.0.1-3"
  }, {
    "product_name" : "Red Hat AMQ Broker 7.12.5",
    "release_date" : "2025-09-22T00:00:00Z",
    "advisory" : "RHSA-2025:16409",
    "cpe" : "cpe:/a:redhat:amq_broker:7.12",
    "package" : "postgresql"
  }, {
    "product_name" : "Red Hat AMQ Broker 7.13.1",
    "release_date" : "2025-08-06T00:00:00Z",
    "advisory" : "RHSA-2025:13274",
    "cpe" : "cpe:/a:redhat:amq_broker:7.13",
    "package" : "postgresql"
  }, {
    "product_name" : "Red Hat build of Apache Camel 4.10.3 for Spring Boot 3.4.7",
    "release_date" : "2025-06-25T00:00:00Z",
    "advisory" : "RHSA-2025:9697",
    "cpe" : "cpe:/a:redhat:apache_camel_spring_boot:4",
    "package" : "postgresql"
  }, {
    "product_name" : "Red Hat build of Quarkus 3.15.6",
    "release_date" : "2025-08-07T00:00:00Z",
    "advisory" : "RHSA-2025:13012",
    "cpe" : "cpe:/a:redhat:quarkus:3.15::el8",
    "package" : "quarkus-bom"
  }, {
    "product_name" : "Red Hat build of Quarkus 3.20.2",
    "release_date" : "2025-08-07T00:00:00Z",
    "advisory" : "RHSA-2025:13010",
    "cpe" : "cpe:/a:redhat:quarkus:3.20::el8",
    "package" : "quarkus-bom"
  } ],
  "package_state" : [ {
    "product_name" : "Red Hat build of Apicurio Registry 2",
    "fix_state" : "Affected",
    "package_name" : "postgresql",
    "cpe" : "cpe:/a:redhat:service_registry:2"
  }, {
    "product_name" : "Red Hat build of Apicurio Registry 3",
    "fix_state" : "Affected",
    "package_name" : "postgresql",
    "cpe" : "cpe:/a:redhat:apicurio_registry:3"
  }, {
    "product_name" : "Red Hat build of Debezium 2",
    "fix_state" : "Not affected",
    "package_name" : "postgresql",
    "cpe" : "cpe:/a:redhat:debezium:2"
  }, {
    "product_name" : "Red Hat build of Debezium 3",
    "fix_state" : "Not affected",
    "package_name" : "postgresql",
    "cpe" : "cpe:/a:redhat:debezium:3"
  }, {
    "product_name" : "Red Hat build of OptaPlanner 8",
    "fix_state" : "Not affected",
    "package_name" : "postgresql",
    "cpe" : "cpe:/a:redhat:optaplanner:::el6"
  }, {
    "product_name" : "Red Hat Data Grid 8",
    "fix_state" : "Not affected",
    "package_name" : "postgresql",
    "cpe" : "cpe:/a:redhat:jboss_data_grid:8"
  }, {
    "product_name" : "Red Hat Enterprise Linux 8",
    "fix_state" : "Not affected",
    "package_name" : "javapackages-tools:201801/maven-assembly-plugin",
    "cpe" : "cpe:/o:redhat:enterprise_linux:8"
  }, {
    "product_name" : "Red Hat Enterprise Linux 8",
    "fix_state" : "Not affected",
    "package_name" : "mariadb:10.3/mariadb",
    "cpe" : "cpe:/o:redhat:enterprise_linux:8"
  }, {
    "product_name" : "Red Hat Enterprise Linux 8",
    "fix_state" : "Not affected",
    "package_name" : "mariadb-devel:10.3/mariadb",
    "cpe" : "cpe:/o:redhat:enterprise_linux:8"
  }, {
    "product_name" : "Red Hat Fuse 7",
    "fix_state" : "Not affected",
    "package_name" : "postgresql",
    "cpe" : "cpe:/a:redhat:jboss_fuse:7"
  }, {
    "product_name" : "Red Hat Integration Camel K 1",
    "fix_state" : "Not affected",
    "package_name" : "postgresql",
    "cpe" : "cpe:/a:redhat:integration:1"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Application Platform 7",
    "fix_state" : "Not affected",
    "package_name" : "postgresql",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform:7"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Application Platform 8",
    "fix_state" : "Not affected",
    "package_name" : "postgresql",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform:8"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Application Platform Expansion Pack",
    "fix_state" : "Not affected",
    "package_name" : "postgresql",
    "cpe" : "cpe:/a:redhat:jbosseapxp"
  }, {
    "product_name" : "Red Hat OpenShift Dev Spaces",
    "fix_state" : "Not affected",
    "package_name" : "devspaces/server-rhel8",
    "cpe" : "cpe:/a:redhat:openshift_devspaces:3"
  }, {
    "product_name" : "Red Hat OpenShift Dev Spaces",
    "fix_state" : "Not affected",
    "package_name" : "devspaces/server-rhel9",
    "cpe" : "cpe:/a:redhat:openshift_devspaces:3"
  }, {
    "product_name" : "Red Hat Process Automation 7",
    "fix_state" : "Not affected",
    "package_name" : "postgresql",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_bpms_platform:7"
  }, {
    "product_name" : "Red Hat Satellite 6",
    "fix_state" : "Not affected",
    "package_name" : "candlepin",
    "cpe" : "cpe:/a:redhat:satellite:6"
  }, {
    "product_name" : "Red Hat Satellite 6",
    "fix_state" : "Not affected",
    "package_name" : "postgresql",
    "cpe" : "cpe:/a:redhat:satellite:6"
  }, {
    "product_name" : "Red Hat Satellite 6",
    "fix_state" : "Not affected",
    "package_name" : "satellite:el8/candlepin",
    "cpe" : "cpe:/a:redhat:satellite:6"
  }, {
    "product_name" : "Red Hat Single Sign-On 7",
    "fix_state" : "Not affected",
    "package_name" : "postgresql",
    "cpe" : "cpe:/a:redhat:red_hat_single_sign_on:7"
  } ],
  "references" : [ "https://www.cve.org/CVERecord?id=CVE-2025-49146\nhttps://nvd.nist.gov/vuln/detail/CVE-2025-49146\nhttps://github.com/pgjdbc/pgjdbc/commit/9217ed16cb2918ab1b6b9258ae97e6ede244d8a0\nhttps://github.com/pgjdbc/pgjdbc/security/advisories/GHSA-hq9p-pm7w-8p54" ],
  "name" : "CVE-2025-49146",
  "mitigation" : {
    "value" : "Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.",
    "lang" : "en:us"
  },
  "csaw" : false
}