Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2021-23222

Опубликовано: 11 нояб. 2021
Источник: redhat
CVSS3: 3.7
EPSS Низкий

Описание

A man-in-the-middle attacker can inject false responses to the client's first few queries, despite the use of SSL certificate verification and encryption.

Отчет

In Red Hat Virtualization the manager appliance uses a vulnerable version of postgresql. Once a fix has been shipped for RHEL 8 the appliance can consume the fix via a regular yum update.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat build of Debezium 1postgresqlNot affected
Red Hat build of QuarkuspostgresqlNot affected
Red Hat Decision Manager 7postgresqlNot affected
Red Hat Enterprise Linux 5postgresqlOut of support scope
Red Hat Enterprise Linux 6postgresqlOut of support scope
Red Hat Enterprise Linux 7postgresqlOut of support scope
Red Hat Enterprise Linux 8postgresql:10/postgresqlNot affected
Red Hat Enterprise Linux 8postgresql:12/postgresqlNot affected
Red Hat Enterprise Linux 8postgresql:13/postgresqlNot affected
Red Hat Enterprise Linux 8postgresql:9.6/postgresqlNot affected

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-522
https://bugzilla.redhat.com/show_bug.cgi?id=2022675postgresql: libpq processes unencrypted bytes from man-in-the-middle

EPSS

Процентиль: 55%
0.00328
Низкий

3.7 Low

CVSS3

Связанные уязвимости

CVSS3: 5.9
ubuntu
больше 3 лет назад

A man-in-the-middle attacker can inject false responses to the client's first few queries, despite the use of SSL certificate verification and encryption.

CVSS3: 5.9
nvd
больше 3 лет назад

A man-in-the-middle attacker can inject false responses to the client's first few queries, despite the use of SSL certificate verification and encryption.

CVSS3: 5.9
msrc
больше 3 лет назад

Описание отсутствует

CVSS3: 5.9
debian
больше 3 лет назад

A man-in-the-middle attacker can inject false responses to the client' ...

rocky
около 3 лет назад

Low: libpq security update

EPSS

Процентиль: 55%
0.00328
Низкий

3.7 Low

CVSS3