Man-in-the-Middle Vulnerability in PostgreSQL
CVE-2021-23222
5.9MEDIUM
What is CVE-2021-23222?
This vulnerability allows a man-in-the-middle attacker to exploit the initial communication between the client and PostgreSQL server. Even with SSL certificate verification and encryption in place, attackers can inject false responses to the client's initial queries. This exposes sensitive data and undermines the integrity of the communication, making it crucial for users to update their PostgreSQL installations to mitigate this risk.
Affected Version(s)
postgresql Affects v9.6 to v14