Pgpool-II is a tool to add useful features to PostgreSQL, including:
Pgpool Global Development Group is pleased to announce the availability of following versions of Pgpool-II:
This release contains a security fix.
If following conditions are all met, the password of "wd_lifecheck_user" is exposed by "SHOW POOL STATUS" command. The command can be executed by any user who can connect to Pgpool-II. (CVE-2023-22332)
In this case it is strongly recommended to upgrade to this version (we do not expose wd_lifecheck_password in show pool_status command any more), or use one of following workarounds.
Workarounds for 4.0.x to 4.4.x users:
In any case we recommend to change "wd_lifecheck_password" in PostgreSQL.
Workarounds for 3.0.x to 3.7.x users:
In any case we recommend to change "wd_lifecheck_password" in PostgreSQL.
Please note that Pgpool-II 3.7.x or before are end of life and no minor updates are provided for those versions.
Please take a look at release notes.
You can download the source code and RPMs.