RHSA-2020:3005: Important: Red Hat Integration Debezium 1.1.3 security update
PostgreSQL is an advanced object-relational database management system. The Debezium PostgreSQL connector includes JDBC driver to access a PostgreSQL database.Security Fix(es): postgresql-jdbc: XML external entity (XXE) vulnerability in PgSQLXML (CVE-2020-13692) For more details about the security issue(s), including the impact, a CVSSscore, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of RHSA-2020:3005?
The severity of RHSA-2020:3005 is classified as important.
What vulnerability is addressed in RHSA-2020:3005?
RHSA-2020:3005 addresses an XML external entity (XXE) vulnerability in the PostgreSQL JDBC driver (CVE-2020-13692).
How do I fix RHSA-2020:3005?
To fix RHSA-2020:3005, you should update to the latest version of the PostgreSQL JDBC driver provided in the advisory.
Who is affected by RHSA-2020:3005?
RHSA-2020:3005 affects users of the PostgreSQL database using the Debezium PostgreSQL connector with the associated JDBC driver.
Is there a workaround for RHSA-2020:3005?
There are no specific workarounds for RHSA-2020:3005; the recommended action is to apply the available security update.