Password can be used past expiry in PgBouncer due to auth_query not taking into account Postgres its VALID UNTIL value, which allows an attacker to log in with an already expired password
| Software | From | Fixed in |
|---|---|---|
| pgbouncer / pgbouncer | - | 1.24.1 |
| debian / debian_linux | 11.0 | 11.0.x |