CVE-2021-23214 log
Source |
|
Severity | High |
Remote | Yes |
Type | Man-in-the-middle |
Description | A security issue has been found in PostgreSQL versions 9.6 up to 14. When the server is configured to use trust authentication with a clientcert requirement or to use cert authentication, a man-in-the-middle attacker can inject arbitrary SQL queries when a connection is first established, despite the use of SSL certificate verification and encryption. |
Group | Package | Affected | Fixed | Severity | Status | Ticket |
---|---|---|---|---|---|---|
AVG-2546 | postgresql | 13.4-6 | 13.5-1 | High | Fixed |
Date | Advisory | Group | Package | Severity | Type |
---|---|---|---|---|---|
04 Apr 2022 | ASA-202204-1 | AVG-2546 | postgresql | High | man-in-the-middle |
References |
---|
https://www.postgresql.org/support/security/CVE-2021-23214/ https://git.postgresql.org/gitweb/?p=postgresql.git;a=commitdiff;h=28e24125541545483093819efae9bca603441951 |
Notes |
---|
This is similar to CVE-2011-0411 (different product) |