Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2021-23214

Опубликовано: 04 мар. 2022
Источник: debian
EPSS Низкий

Описание

When the server is configured to use trust authentication with a clientcert requirement or to use cert authentication, a man-in-the-middle attacker can inject arbitrary SQL queries when a connection is first established, despite the use of SSL certificate verification and encryption.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
postgresql-14fixed14.1-1package
postgresql-13unfixedpackage
postgresql-11removedpackage
postgresql-9.6removedpackage

Примечания

  • https://www.postgresql.org/about/news/postgresql-141-135-129-1114-1019-and-9624-released-2349/

  • https://git.postgresql.org/gitweb/?p=postgresql.git;a=commitdiff;h=046c2c846b741a12e7fd61d8d86bf324a20e3dfc (REL9_6_24)

EPSS

Процентиль: 52%
0.0029
Низкий

Связанные уязвимости

CVSS3: 8.1
ubuntu
больше 3 лет назад

When the server is configured to use trust authentication with a clientcert requirement or to use cert authentication, a man-in-the-middle attacker can inject arbitrary SQL queries when a connection is first established, despite the use of SSL certificate verification and encryption.

CVSS3: 8.1
redhat
больше 3 лет назад

When the server is configured to use trust authentication with a clientcert requirement or to use cert authentication, a man-in-the-middle attacker can inject arbitrary SQL queries when a connection is first established, despite the use of SSL certificate verification and encryption.

CVSS3: 8.1
nvd
больше 3 лет назад

When the server is configured to use trust authentication with a clientcert requirement or to use cert authentication, a man-in-the-middle attacker can inject arbitrary SQL queries when a connection is first established, despite the use of SSL certificate verification and encryption.

CVSS3: 8.1
msrc
больше 3 лет назад

Описание отсутствует

rocky
около 3 лет назад

Moderate: postgresql:10 security update

EPSS

Процентиль: 52%
0.0029
Низкий