A man-in-the-middle attacker can inject false responses...
Moderate severity Unreviewed PublishedMar 4, 2022 to the GitHub Advisory Database • UpdatedFeb 2, 2023
Description
A man-in-the-middle attacker can inject false responses to the client's first few queries, despite the use of SSL certificate verification and encryption.
References
- https://nvd.nist.gov/vuln/detail/CVE-2021-23222
- postgres/postgres@160c025
- https://bugzilla.redhat.com/show_bug.cgi?id=2022675
- https://git.postgresql.org/gitweb/?p=postgresql.git;a=commitdiff;h=d83cdfdca9d918bbbd6bb209139b94c954da7228
- https://www.postgresql.org/support/security/CVE-2021-23222/
- https://security.gentoo.org/glsa/202211-04
Published by theNational Vulnerability DatabaseMar 2, 2022
Published to the GitHub Advisory DatabaseMar 4, 2022
Last updatedFeb 2, 2023
Severity
Moderate / 10
CVSS v3 base metrics
Attack vector
Network
Attack complexity
High
Privileges required
None
User interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
None
Availability
None
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
EPSS score
(58th percentile)
Weaknesses
WeaknessCWE-522
Insufficiently Protected Credentials
The product transmits or stores authentication credentials, but it uses an insecure method that is susceptible to unauthorized interception and/or retrieval.Learn more on MITRE.CVE ID
CVE-2021-23222
GHSA ID
GHSA-735f-7qx4-jqq5
Source code
No known source code
Dependabot alerts are not supported on this advisory because it does not have a package from a supported ecosystem with an affected and fixed version.
LoadingChecking history
Uh oh!
There was an error while loading.Please reload this page.
See something to contribute?Suggest improvements for this vulnerability.