CVE-2021-23222

Severity CVSS v4.0:
Pending analysis
Type:
CWE-522 Insufficiently Protected Credentials
Publication date:
02/03/2022
Last modified:
07/11/2023

Description

A man-in-the-middle attacker can inject false responses to the client's first few queries, despite the use of SSL certificate verification and encryption.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:postgresql:postgresql:*:*:*:*:*:*:*:* 9.6 (including) 9.6.24 (excluding)
cpe:2.3:a:postgresql:postgresql:*:*:*:*:*:*:*:* 10.0 (including) 10.19 (excluding)
cpe:2.3:a:postgresql:postgresql:*:*:*:*:*:*:*:* 11.0 (including) 11.14 (excluding)
cpe:2.3:a:postgresql:postgresql:*:*:*:*:*:*:*:* 12.0 (including) 12.9 (excluding)
cpe:2.3:a:postgresql:postgresql:*:*:*:*:*:*:*:* 13.0 (including) 13.5 (excluding)
cpe:2.3:a:postgresql:postgresql:14.0:*:*:*:*:*:*:*