pgsync before 0.6.7 is affected by Information Disclosure of sensitive information. Syncing the schema with the --schema-first
and --schema-only
options is mishandled. For example, the sslmode connection parameter may be lost, which means that SSL would not be used.
{ "nvd_published_at": "2021-04-27T03:15:00Z", "cwe_ids": [ "CWE-319" ], "severity": "HIGH", "github_reviewed": true, "github_reviewed_at": "2021-04-27T15:54:16Z" }