Msrc Cm1 Postgresql 12.7-2 On Cbl Mariner 1.0 vulnerabilities
2 known vulnerabilities affecting msrc/cm1_postgresql_12.7-2_on_cbl_mariner_1.0.
Total CVEs
2
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
HIGH1MEDIUM1
Vulnerabilities
Page 1 of 1
CVE-2021-23214HIGHCVSS 8.12022-03-08
CVE-2021-23214 [HIGH] CWE-89 When the server is configured to use trust authentication with a clientcert requirement or to use cert authentication a man-in-the-middle attacker can inject arbitrary SQL queries when a connection is
When the server is configured to use trust authentication with a clientcert requirement or to use cert authentication a man-in-the-middle attacker can inject arbitrary SQL queries when a connection is first established despite the use of SSL certificate verification and
msrc
CVE-2021-23222MEDIUMCVSS 5.92022-03-08
CVE-2021-23222 [MEDIUM] CWE-522 A man-in-the-middle attacker can inject false responses to the client's first few queries despite the use of SSL certificate verification and encryption.
A man-in-the-middle attacker can inject false responses to the client's first few queries despite the use of SSL certificate verification and encryption.
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the m
msrc