CVE-2021-23222
published 2022-03-02CVE-2021-23222: A man-in-the-middle attacker can inject false responses to the client's first few queries, despite the use of SSL certificate verification and encryption.
PriorityP428medium5.9CVSS 3.1
AVNACHPRNUINSUCHINAN
EPSS
1.50%
71.5th percentile
A man-in-the-middle attacker can inject false responses to the client's first few queries, despite the use of SSL certificate verification and encryption.
Affected
12 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | postgresql-13 | < postgresql-13 13.5-0+deb11u1 (bullseye) | postgresql-13 13.5-0+deb11u1 (bullseye) |
| github.com | vapor_postgres-nio | >= 0 < 1.14.2 | 1.14.2 |
| msrc | cbl2_postgresql_14.2-1_on_cbl_mariner_2.0 | — | — |
| msrc | cm1_postgresql_12.12-1_on_cbl_mariner_1.0 | — | — |
| msrc | cm1_postgresql_12.7-2_on_cbl_mariner_1.0 | — | — |
| postgresql | postgresql | — | — |
| postgresql | postgresql | >= 10.0 < 10.19 | 10.19 |
| postgresql | postgresql | >= 11.0 < 11.14 | 11.14 |
| postgresql | postgresql | >= 12.0 < 12.9 | 12.9 |
| postgresql | postgresql | >= 13.0 < 13.5 | 13.5 |
| postgresql | postgresql | >= 9.6 < 9.6.24 | 9.6.24 |
| postgresql | postgresql | >= 9.6.0 < 9.6.24 | 9.6.24 |
CVSS provenance
nvdv3.15.9MEDIUMCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:P/I:N/A:N
ghsa8.1HIGH
osv8.1HIGH
vendor_debian5.9MEDIUM
vendor_msrc5.9MEDIUM
vendor_redhat5.9MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
PostgreSQL vulnerability
vendor_ubuntu·2022-12-07
CVE-2021-23222 PostgreSQL vulnerability
Title: PostgreSQL vulnerability
Summary: PostgreSQL could allow unintended access to network services.
Jacob Champion discovered that PostgreSQL incorrectly handled SSL
certificate verification and encryption. A remote attacker could possibly
use this issue to inject arbitrary SQL queries when a connection is first
established.
Instructions: After a standard system update you need to restart PostgreSQL to make all the
necessary changes.
Microsoft
Odyssey passes to client unencrypted bytes from man-in-the-middle When Odyssey storage is configured to use the PostgreSQL server using 'trust' authentication with a 'clientcert' requirement or to use
vendor_msrc·2022-08-09·CVSS 5.9
CVE-2021-43767 [MEDIUM] CWE-295 Odyssey passes to client unencrypted bytes from man-in-the-middle When Odyssey storage is configured to use the PostgreSQL server using 'trust' authentication with a 'clientcert' requirement or to use
Odyssey passes to client unencrypted bytes from man-in-the-middle When Odyssey storage is configured to use the PostgreSQL server using 'trust' authentication with a 'clientcert' requirement or to use 'cert' authentication a man-in-the-middle attacker can inject false responses to the client's first few queries. Despite the use of SSL certificate verification and encryption Odyssey will pass these results to client as if they originated from valid server. This is similar to CVE-2021-23222 for PostgreSQL.
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recen
Microsoft
A man-in-the-middle attacker can inject false responses to the client's first few queries despite the use of SSL certificate verification and encryption.
vendor_msrc·2022-03-08·CVSS 5.9
CVE-2021-23222 [MEDIUM] CWE-522 A man-in-the-middle attacker can inject false responses to the client's first few queries despite the use of SSL certificate verification and encryption.
A man-in-the-middle attacker can inject false responses to the client's first few queries despite the use of SSL certificate verification and encryption.
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparency in this work which is why we began publishing CSAF/VEX in October 2025. See this blog post for more information. If impact to additional products is identified, we will update the CVE to reflect this.
Mariner: Mariner
redhat
Ubuntu
PostgreSQL vulnerabilities
vendor_ubuntu·2021-11-11
CVE-2021-23222 PostgreSQL vulnerabilities
Title: PostgreSQL vulnerabilities
Summary: PostgreSQL could allow unintended access to network services.
Jacob Champion discovered that PostgreSQL incorrectly handled SSL
certificate verification and encryption. A remote attacker could possibly
use this issue to inject arbitrary SQL queries when a connection is first
established.
Instructions: This update uses a new upstream release, which includes additional bug
fixes. After a standard system update you need to restart PostgreSQL to
make all the necessary changes.
Red Hat
postgresql: libpq processes unencrypted bytes from man-in-the-middle
vendor_redhat·2021-11-11·CVSS 5.9
CVE-2021-23222 [MEDIUM] CWE-522 postgresql: libpq processes unencrypted bytes from man-in-the-middle
postgresql: libpq processes unencrypted bytes from man-in-the-middle
A man-in-the-middle attacker can inject false responses to the client's first few queries, despite the use of SSL certificate verification and encryption.
Statement: In Red Hat Virtualization the manager appliance uses a vulnerable version of postgresql. Once a fix has been shipped for RHEL 8 the appliance can consume the fix via a regular yum update.
Package: postgresql (Red Hat build of Debezium 1) - Not affected
Package: postgresql (Red Hat build of Quarkus) - Not affected
Package: postgresql (Red Hat Decision Manager 7) - Not affected
Package: postgresql (Red Hat Enterprise Linux 5) - Out of support scope
Package: postgresql (Red Hat Enterprise Linux 6) - Out of support scope
Package: postgresql (Red Hat Enter
Debian
CVE-2021-23222: postgresql-13 - A man-in-the-middle attacker can inject false responses to the client's first fe...
vendor_debian·2021·CVSS 5.9
CVE-2021-23222 [MEDIUM] CVE-2021-23222: postgresql-13 - A man-in-the-middle attacker can inject false responses to the client's first fe...
A man-in-the-middle attacker can inject false responses to the client's first few queries, despite the use of SSL certificate verification and encryption.
Scope: local
bullseye: resolved (fixed in 13.5-0+deb11u1)
GHSA
PostgresNIO processes unencrypted bytes from man-in-the-middle
ghsa·2023-05-10·CVSS 8.1
CVE-2023-31136 [HIGH] CWE-522 PostgresNIO processes unencrypted bytes from man-in-the-middle
PostgresNIO processes unencrypted bytes from man-in-the-middle
### Impact
Any user of PostgresNIO connecting to servers with TLS enabled is vulnerable to a man-in-the-middle attacker injecting false responses to the client's first few queries, despite the use of TLS certificate verification and encryption.
_The remaining text in this section is quoted verbatim from [PostgreSQL's CVE-2021-23222 advisory](https://www.postgresql.org/support/security/CVE-2021-23222/):_
> If more preconditions hold, the attacker can exfiltrate the client's password or other confidential data that might be transmitted early in a session. The attacker must have a way to trick the client's intended server into making the confidential data accessible to the attacker. A known implementation having that property i
OSV
PostgresNIO processes unencrypted bytes from man-in-the-middle
osv·2023-05-10·CVSS 8.1
CVE-2023-31136 [HIGH] PostgresNIO processes unencrypted bytes from man-in-the-middle
PostgresNIO processes unencrypted bytes from man-in-the-middle
### Impact
Any user of PostgresNIO connecting to servers with TLS enabled is vulnerable to a man-in-the-middle attacker injecting false responses to the client's first few queries, despite the use of TLS certificate verification and encryption.
_The remaining text in this section is quoted verbatim from [PostgreSQL's CVE-2021-23222 advisory](https://www.postgresql.org/support/security/CVE-2021-23222/):_
> If more preconditions hold, the attacker can exfiltrate the client's password or other confidential data that might be transmitted early in a session. The attacker must have a way to trick the client's intended server into making the confidential data accessible to the attacker. A known implementation having that property i
GHSA
GHSA-xmm7-85wh-j3jf: Odyssey passes to client unencrypted bytes from man-in-the-middle When Odyssey storage is configured to use the PostgreSQL server using 'trust' authen
ghsa_unreviewed·2022-08-26·CVSS 5.9
CVE-2021-43767 [MEDIUM] CWE-295 GHSA-xmm7-85wh-j3jf: Odyssey passes to client unencrypted bytes from man-in-the-middle When Odyssey storage is configured to use the PostgreSQL server using 'trust' authen
Odyssey passes to client unencrypted bytes from man-in-the-middle When Odyssey storage is configured to use the PostgreSQL server using 'trust' authentication with a 'clientcert' requirement or to use 'cert' authentication, a man-in-the-middle attacker can inject false responses to the client's first few queries. Despite the use of SSL certificate verification and encryption, Odyssey will pass these results to client as if they originated from valid server. This is similar to CVE-2021-23222 for PostgreSQL.
GHSA
GHSA-735f-7qx4-jqq5: A man-in-the-middle attacker can inject false responses to the client's first few queries, despite the use of SSL certificate verification and encrypt
ghsa_unreviewed·2022-03-04
CVE-2021-23222 [MEDIUM] CWE-522 GHSA-735f-7qx4-jqq5: A man-in-the-middle attacker can inject false responses to the client's first few queries, despite the use of SSL certificate verification and encrypt
A man-in-the-middle attacker can inject false responses to the client's first few queries, despite the use of SSL certificate verification and encryption.
OSV
CVE-2021-23222: A man-in-the-middle attacker can inject false responses to the client's first few queries, despite the use of SSL certificate verification and encrypt
osv·2022-03-02·CVSS 5.9
CVE-2021-23222 [MEDIUM] CVE-2021-23222: A man-in-the-middle attacker can inject false responses to the client's first few queries, despite the use of SSL certificate verification and encrypt
A man-in-the-middle attacker can inject false responses to the client's first few queries, despite the use of SSL certificate verification and encryption.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://bugzilla.redhat.com/show_bug.cgi?id=2022675https://git.postgresql.org/gitweb/?p=postgresql.git%3Ba=commitdiff%3Bh=d83cdfdca9d918bbbd6bb209139b94c954da7228https://github.com/postgres/postgres/commit/160c0258802d10b0600d7671b1bbea55d8e17d45https://security.gentoo.org/glsa/202211-04https://www.postgresql.org/support/security/CVE-2021-23222/https://bugzilla.redhat.com/show_bug.cgi?id=2022675https://git.postgresql.org/gitweb/?p=postgresql.git%3Ba=commitdiff%3Bh=d83cdfdca9d918bbbd6bb209139b94c954da7228https://github.com/postgres/postgres/commit/160c0258802d10b0600d7671b1bbea55d8e17d45https://security.gentoo.org/glsa/202211-04https://www.postgresql.org/support/security/CVE-2021-23222/
2022-03-02
Published