Man-in-the-Middle Vulnerability in PostgreSQL
CVE-2021-23222

5.9MEDIUM

Key Information:

Vendor
Postgresql
Vendor
CVE Published:
2 March 2022

Summary

This vulnerability allows a man-in-the-middle attacker to exploit the initial communication between the client and PostgreSQL server. Even with SSL certificate verification and encryption in place, attackers can inject false responses to the client's initial queries. This exposes sensitive data and undermines the integrity of the communication, making it crucial for users to update their PostgreSQL installations to mitigate this risk.

Affected Version(s)

postgresql Affects v9.6 to v14

References

CVSS V3.1

Score:
5.9
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.