Описание
When the server is configured to use trust authentication with a clientcert requirement or to use cert authentication, a man-in-the-middle attacker can inject arbitrary SQL queries when a connection is first established, despite the use of SSL certificate verification and encryption.
It was found that a PostgreSQL server could accept plain text data during the establishment of an SSL connection. When a user is requesting a certificate based authentication, an active Person in the Middle could use this flaw in order to inject arbitrary SQL commands.
Отчет
In Red Hat Virtualization the manager appliance uses a vulnerable version of postgresql. Once a fix has been shipped for RHEL 8 the appliance can consume the fix via a regular yum update.
Затронутые пакеты
Платформа | Пакет | Состояние | Рекомендация | Релиз |
---|---|---|---|---|
Red Hat build of Debezium 1 | postgresql | Not affected | ||
Red Hat build of Quarkus | postgresql | Not affected | ||
Red Hat Decision Manager 7 | postgresql | Not affected | ||
Red Hat Enterprise Linux 5 | postgresql | Out of support scope | ||
Red Hat Enterprise Linux 6 | postgresql | Out of support scope | ||
Red Hat Enterprise Linux 7 | postgresql | Out of support scope | ||
Red Hat Enterprise Linux 8 | libpq | Not affected | ||
Red Hat Enterprise Linux 8 | postgresql:9.6/postgresql | Will not fix | ||
Red Hat Enterprise Linux 9 | postgresql | Not affected | ||
Red Hat Fuse 7 | postgresql | Not affected |
Показывать по
Дополнительная информация
Статус:
EPSS
8.1 High
CVSS3
Связанные уязвимости
When the server is configured to use trust authentication with a clientcert requirement or to use cert authentication, a man-in-the-middle attacker can inject arbitrary SQL queries when a connection is first established, despite the use of SSL certificate verification and encryption.
When the server is configured to use trust authentication with a clientcert requirement or to use cert authentication, a man-in-the-middle attacker can inject arbitrary SQL queries when a connection is first established, despite the use of SSL certificate verification and encryption.
When the server is configured to use trust authentication with a clien ...
EPSS
8.1 High
CVSS3