CVE-2020-13692: Debian Linux

High severity, CVSS 7.7. EPSS: 4.1% chance of exploitation in the next 30 days.

PostgreSQL JDBC Driver (aka PgJDBC) before 42.2.13 allows XXE.

Affected products

  • Debian Debian Linux: version 10.0 only; version 11.0 only
  • Fedoraproject Fedora: version 32 only
  • Netapp Steelstore Cloud Integrated Storage: affected versions not specified
  • PostgreSQL PostgreSQL Jdbc Driver: before 42.2.13 (fixed in 42.2.13)
  • Quarkus Quarkus: up to and including 1.5.2

Published 2020-06-04. Last modified 2026-06-17.