CVE-2021-23214

Severity CVSS v4.0:
Pending analysis
Type:
CWE-89 SQL Injection
Publication date:
04/03/2022
Last modified:
07/11/2023

Description

When the server is configured to use trust authentication with a clientcert requirement or to use cert authentication, a man-in-the-middle attacker can inject arbitrary SQL queries when a connection is first established, despite the use of SSL certificate verification and encryption.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:postgresql:postgresql:*:*:*:*:*:*:*:* 9.6.24 (excluding)
cpe:2.3:a:postgresql:postgresql:*:*:*:*:*:*:*:* 10.0 (including) 10.19 (excluding)
cpe:2.3:a:postgresql:postgresql:*:*:*:*:*:*:*:* 11.0 (including) 11.14 (excluding)
cpe:2.3:a:postgresql:postgresql:*:*:*:*:*:*:*:* 12.0 (including) 12.9 (excluding)
cpe:2.3:a:postgresql:postgresql:*:*:*:*:*:*:*:* 13.0 (including) 13.5 (excluding)
cpe:2.3:a:postgresql:postgresql:14.0:*:*:*:*:*:*:*
cpe:2.3:o:fedoraproject:fedora:34:*:*:*:*:*:*:*
cpe:2.3:o:fedoraproject:fedora:35:*:*:*:*:*:*:*
cpe:2.3:a:redhat:software_collections:1.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux:8.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux_for_ibm_z_systems:8.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux_for_power_little_endian:8.0:*:*:*:*:*:*:*