CVE-2025-22248 Details
Description
The bitnami/pgpool Docker image, and the bitnami/postgres-ha k8s chart, under default configurations, comes with an 'repmgr' user that allows unauthenticated access to the database inside the cluster. The PGPOOL_SR_CHECK_USER is the user that Pgpool itself uses to perform streaming replication checks against nodes, and should not be at trust level. This allows to log into a PostgreSQL database using the repgmr user without authentication. If Pgpool is exposed externally, a potential attacker could use this user to get access to the service. This is also present within the bitnami/postgres-ha Kubernetes Helm chart.
A vulnerability exists in the Bitnami Pgpool Docker image and the Bitnami Postgres-HA Kubernetes Helm chart, both under default configurations. They include a 'repmgr' user that allows unauthenticated access to the database within the cluster. The 'PGPOOL_SR_CHECK_USER' is utilized by Pgpool for streaming replication checks and should not be set to trust level. This misconfiguration enables logging into a PostgreSQL database using the 'repmgr' user without authentication. If Pgpool is exposed externally, an attacker could potentially access the service. This issue is present in Bitnami Pgpool II versions prior to 4.6.0-1 (included in the container image 4.6.0-debian-12-r8) and in Bitnami Postgres-HA Helm chart versions prior to 16.0.0.
Users are advised to upgrade Bitnami Pgpool II to version 4.6.0-1 or later (container image 4.6.0-debian-12-r8). For the Bitnami Postgres-HA Helm chart, upgrade to version 16.0.0 or later.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed May 13, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/bitnami/charts/security/advisories/GHSA-mx38-x658-5fwj | [email protected] | Vendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-1188 | Initialization of a Resource with an Insecure Default | CISA-ADP |
Affected Products
| Product | Versions |
|---|---|
| broadcom bitnami | < 16.0.0 |
CPE
Remediation
| |
| broadcom bitnami/pgpool | < 4.6.0-1 |
CPE
Remediation
| |
Change History
6 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jul 18, 2025 | Reanalysis | [email protected] |
| Jul 16, 2025 | Initial Analysis | [email protected] |
| May 13, 2025 | CVE Modified | CISA-ADP |
| May 13, 2025 | New CVE Received | [email protected] |