Pgsync Contains Cleartext Transmission of Sensitive Information
High severity
GitHub Reviewed
Published
Apr 27, 2021
to the GitHub Advisory Database
•
Updated Aug 25, 2023
Description
Published by the National Vulnerability Database
Apr 27, 2021
Reviewed
Apr 27, 2021
Published to the GitHub Advisory Database
Apr 27, 2021
Last updated
Aug 25, 2023
pgsync before 0.6.7 is affected by Information Disclosure of sensitive information. Syncing the schema with the
--schema-first
and--schema-only
options is mishandled. For example, the sslmode connection parameter may be lost, which means that SSL would not be used.References