CVE-2021-31671: Cleartext Transmission of Sensitive Information
(updated )
pgsync Syncing the schema with the --schema-first
and --schema-only
options is mishandled. For example, the sslmode connection parameter may be lost, which means that SSL would not be used.
References
Detect and mitigate CVE-2021-31671 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →