CVE-2020-13692 (https://nvd.nist.gov/vuln/detail/CVE-2020-13692): PostgreSQL JDBC Driver (aka PgJDBC) before 42.2.13 allows XXE.
The bug has been referenced in the following commit(s): https://gitweb.gentoo.org/repo/gentoo.git/commit/?id=814848b7060d05539e395d8c3e5d9409b8b89e09 commit 814848b7060d05539e395d8c3e5d9409b8b89e09 Author: Volkmar W. Pogatzki <gentoo@pogatzki.net> AuthorDate: 2022-06-15 06:16:12 +0000 Commit: Florian Schmaus <flow@gentoo.org> CommitDate: 2022-06-20 06:49:25 +0000 dev-java/jdbc-postgresql: add 42.4.0 Bug: https://bugs.gentoo.org/727906 Closes: https://bugs.gentoo.org/851993 Signed-off-by: Volkmar W. Pogatzki <gentoo@pogatzki.net> Closes: https://github.com/gentoo/gentoo/pull/25911 Signed-off-by: Florian Schmaus <flow@gentoo.org> dev-java/jdbc-postgresql/Manifest | 1 + .../jdbc-postgresql/jdbc-postgresql-42.4.0.ebuild | 59 ++++++++++++++++++++++ 2 files changed, 60 insertions(+)
Thanks! Please stable when ready