Skip to content

Commit c78d691

Browse files
djw-mjosh-heyer
authored andcommitted
Update cve-2025-2291.mdx - Added products
1 parent df475ba commit c78d691

File tree

1 file changed

+7
-3
lines changed

1 file changed

+7
-3
lines changed

advocacy_docs/security/assessments/cve-2025-2291.mdx

+7-3
Original file line numberDiff line numberDiff line change
@@ -1,12 +1,12 @@
11
---
22
title: CVE-2025-2291 - PgBouncer "VALID UNTIL yesterday"
33
navTitle: CVE-2025-2291
4-
affectedProducts: All versions of PGBouncer prior to 1.24.1
4+
affectedProducts: All versions of PGBouncer prior to 1.24.1, TPA prior to 23.38.0, PGAI Cloud Service prior to May 12, 2025
55
---
66

7-
First Published: 2025/04/28
7+
First Published: 2025/04/30
88

9-
Last Updated: 2025/04/28
9+
Last Updated: 2025/04/30
1010

1111
Important: This is an assessment of the impact of CVE-2025-2291 on EDB products and services. It links to and details the CVE and supplements that information with EDB's own assessment.
1212

@@ -29,15 +29,19 @@ CVSS Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
2929

3030
## Affected products and versions
3131

32+
* Community PgBouncer: All versions prior to 1.24.1
3233
* EDB PgBouncer: All versions prior to 1.24.1
3334
* EDB TPA: All versions prior to 23.38.0
35+
* PGAI Cloud Service: All versions prior to May 12, 2025 release.
3436

3537
## Remediation/fixes
3638

3739
| Product | VRMF | Remediation/First Fix |
3840
|---------------|---------|---------------------------------------|
41+
| Community PgBouncer | 1.24.1 | Upgrade to Community PgBouncer 1.24.1 |
3942
| EDB PgBouncer | 1.24.1 | Upgrade to EDB PgBouncer 1.24.1 |
4043
| EDB TPA | 23.38.0 | Upgrade to TPA 23.38.0 when available |
44+
| PGAI Cloud Service | May 12, 2025 | Resolved by May 12, 2025 Release |
4145

4246
For TPA we recommend applying the following mitigation measures until the upcoming version with a fix is available:
4347

0 commit comments

Comments
 (0)