{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/cpes/cpe2.3aquarkusquarkus/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:postgresql:postgresql_jdbc_driver:*:*:*:*:*:*:*:*","cpe:2.3:a:postgresql:postgresql_jdbc_driver:42.3.2:rc1:*:*:*:*:*:*","cpe:2.3:o:fedoraproject:fedora:35:*:*:*:*:*:*:*","cpe:2.3:a:quarkus:quarkus:*:*:*:*:*:*:*:*","cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:*","cpe:2.3:o:debian:debian_linux:10.0:*:*:*:*:*:*:*","cpe:2.3:o:debian:debian_linux:11.0:*:*:*:*:*:*:*","cpe:2.3:a:postgresql:postgresql_jdbc_driver:42.4.0:*:*:*:*:*:*:*","cpe:2.3:a:postgresql:postgresql_jdbc_driver:42.4.1:rc1:*:*:*:*:*:*","cpe:2.3:o:fedoraproject:fedora:36:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":7,"id":"CVE-2022-21724"},{"cvss":7.1,"id":"CVE-2022-31197"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["PostgreSQL JDBC Driver"],"_cs_severities":["medium"],"_cs_tags":[],"_cs_type":"advisory","_cs_vendors":["PostgreSQL"],"content_html":"\u003cp\u003eThe PostgreSQL JDBC Driver is affected by multiple security vulnerabilities, specifically tracked under CVE-2022-21724 and CVE-2022-31197. These vulnerabilities arise from improper handling of connection properties and authentication mechanisms within the driver. An attacker capable of influencing the connection parameters or environment where the driver operates could potentially exploit these flaws to bypass intended security controls. Successful exploitation allows for unauthorized data manipulation and the disclosure of sensitive information within applications that rely on the affected PostgreSQL JDBC Driver for database connectivity. Defenders should prioritize updating the driver to a patched version across all integrated environments to mitigate the risk of unauthorized database interactions.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of these vulnerabilities can lead to the loss of data integrity via unauthorized modification and the compromise of confidentiality through the exposure of sensitive database content. Organizations utilizing Java-based applications that interface with PostgreSQL databases are primarily at risk, as the JDBC driver is a core dependency for these connections. The potential impact ranges from localized data leaks to broader application-level compromises depending on the application's implementation of database authentication and authorization.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003ePrioritize auditing the software inventory to identify all applications and services currently utilizing the PostgreSQL JDBC Driver. Evaluate these instances against the patched version requirements provided by the PostgreSQL project and ensure all affected instances are updated to versions that contain security fixes for CVE-2022-21724 and CVE-2022-31197. If immediate patching is not possible, review application connection configurations to identify and restrict any untrusted input that could influence JDBC connection properties or connection strings.\u003c/p\u003e\n","date_modified":"2026-10-08T19:18:23Z","date_published":"2026-10-08T19:18:23Z","id":"https://feed.craftedsignal.io/briefs/2026-10-postgresql-jdbc-vulnerabilities/","summary":"The PostgreSQL JDBC Driver is susceptible to multiple vulnerabilities, including CVE-2022-21724 and CVE-2022-31197, that allow remote attackers to manipulate data and disclose sensitive information.","title":"Multiple Vulnerabilities in PostgreSQL JDBC Driver","url":"https://feed.craftedsignal.io/briefs/2026-10-postgresql-jdbc-vulnerabilities/"}],"language":"en","title":"CraftedSignal Threat Feed - Cpe:2.3:a:quarkus:quarkus:*:*:*:*:*:*:*:*","version":"https://jsonfeed.org/version/1.1"}