Information Exposure Affecting pgsync package, versions <0.6.7


0.0
medium

Snyk CVSS

    Attack Complexity Low

    Threat Intelligence

    EPSS 0.31% (70th percentile)
Expand this section
NVD
7.5 high

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk ID SNYK-RUBY-PGSYNC-1277110
  • published 27 Apr 2021
  • disclosed 27 Apr 2021
  • credit Dmitriy Gunchenko

How to fix?

Upgrade pgsync to version 0.6.7 or higher.

Overview

pgsync is a Sync Postgres data between databases.

Affected versions of this package are vulnerable to Information Exposure due to mishandling of schema syncing using the --schema-first and --schema-only flags, which may result in dropping security parameters.