1 results (0.001 seconds)

CVSS: 9.4EPSS: 0%CPEs: 1EXPL: 0

13 May 2025 — The bitnami/pgpool Docker image, and the bitnami/postgres-ha k8s chart, under default configurations, comes with an 'repmgr' user that allows unauthenticated access to the database inside the cluster. The PGPOOL_SR_CHECK_USER is the user that Pgpool itself uses to perform streaming replication checks against nodes, and should not be at trust level. This allows to log into a PostgreSQL database using the repgmr user without authentication. If Pgpool is exposed externally, a potential attacker could use this ... • https://github.com/bitnami/charts/security/advisories/GHSA-mx38-x658-5fwj • CWE-1188: Initialization of a Resource with an Insecure Default •