cbcvebase.
CVE-2021-23214
published 2022-03-04

CVE-2021-23214: When the server is configured to use trust authentication with a clientcert requirement or to use cert authentication, a man-in-the-middle attacker can inject…

high8.1CVSS 3.1
AVNACHPRNUINSUCHIHAH
When the server is configured to use trust authentication with a clientcert requirement or to use cert authentication, a man-in-the-middle attacker can inject arbitrary SQL queries when a connection is first established, despite the use of SSL certificate verification and encryption.

Affected

18 ranges
VendorProductVersion rangeFixed in
debianpostgresql-13< postgresql-13 13.5-0+deb11u1 (bullseye)postgresql-13 13.5-0+deb11u1 (bullseye)
fedoraprojectfedora
fedoraprojectfedora
github.comvapor_postgres-nio>= 0 < 1.14.21.14.2
msrccbl2_postgresql_14.2-1_on_cbl_mariner_2.0
msrccm1_postgresql_12.12-1_on_cbl_mariner_1.0
msrccm1_postgresql_12.7-2_on_cbl_mariner_1.0
odyssey_projectodyssey
postgresqlpostgresql< 9.6.249.6.24
postgresqlpostgresql
postgresqlpostgresql>= 10.0 < 10.1910.19
postgresqlpostgresql>= 11.0 < 11.1411.14
postgresqlpostgresql>= 12.0 < 12.912.9
postgresqlpostgresql>= 13.0 < 13.513.5
redhatenterprise_linux
redhatenterprise_linux_for_ibm_z_systems
redhatenterprise_linux_for_power_little_endian
redhatsoftware_collections

CVSS provenance

nvdv3.18.1HIGHCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
ghsa8.1HIGH
osv8.1HIGH