CVE-2021-23222

Description

A man-in-the-middle attacker can inject false responses to the clients first few queries, despite the use of SSL certificate verification and encryption.

Risk Information

Base Score
5.9
MODERATE
Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
EPSS Score
Exploitation Probability
0.282

Associated Vulnerability

VulnerabilityOS Platform
Vulnerabilities CVE-2021-23222 Announcement,CVE-2021-23214 Announcement are fixed in Postgresql 14.1Windows
Vulnerabilities CVE-2021-23222,CVE-2021-23214 are fixed in PostgreSQL 14.1Windows
Vulnerabilities CVE-2021-23222,CVE-2021-23214 are fixed in PostgreSQL 13.5Windows
Vulnerabilities CVE-2021-23222,CVE-2021-23214 are fixed in PostgreSQL 12.9Windows
Vulnerabilities CVE-2021-23222,CVE-2021-23214 are fixed in PostgreSQL 11.14Windows
Vulnerabilities CVE-2021-23222,CVE-2021-23214 are fixed in PostgreSQL 10.19Windows
Vulnerabilities CVE-2021-23222,CVE-2021-23214 are fixed in PostgreSQL 9.6.24Windows
Multiple Vulnerabilities are affected in IBM Security Guardium 11.1Windows
Multiple Vulnerabilities are affected in IBM Security Guardium 11.2Windows
Multiple Vulnerabilities are affected in IBM Security Guardium 11.3Windows
Multiple Vulnerabilities are affected in IBM Security Guardium 11.4Windows
Multiple Vulnerabilities are affected in IBM Security Guardium 11.0Windows
postgresql-11 security update(DSA-5006-1) postgresql-11_11.14-0+deb10u1_i386.debLinux
postgresql-11 security update(DSA-5006-1) postgresql-11_11.14-0+deb10u1_amd64.debLinux
Object-relational SQL database (USN-5145-1) postgresql-10_10.22-0ubuntu0.18.04.1_i386.debLinux
Object-relational SQL database (USN-5145-1) postgresql-10_10.22-0ubuntu0.18.04.1_amd64.debLinux
Object-relational SQL database (USN-5145-1) postgresql-12_12.12-0ubuntu0.20.04.1_i386.debLinux
Object-relational SQL database (USN-5145-1) postgresql-12_12.12-0ubuntu0.20.04.1_amd64.debLinux
Object-relational SQL database (USN-5145-1) postgresql-13_13.5-0ubuntu0.21.04.1_i386.debLinux
Object-relational SQL database (USN-5145-1) postgresql-13_13.5-0ubuntu0.21.04.1_amd64.debLinux
Object-relational SQL database (USN-5145-1) postgresql-13_13.7-0ubuntu0.21.10.1_i386.debLinux
Object-relational SQL database (USN-5145-1) postgresql-13_13.7-0ubuntu0.21.10.1_amd64.debLinux
SUSE-SU-2021:3761-1(SUSE Linux Enterprise Server 12-SP5 ) postgresql10-10.19-4.22.1.x86_64.rpmLinux
SUSE-SU-2021:3761-1(SUSE Linux Enterprise Server 12-SP5 ) postgresql10-contrib-10.19-4.22.1.x86_64.rpmLinux
SUSE-SU-2021:3761-1(SUSE Linux Enterprise Server 12-SP5 ) postgresql10-contrib-debuginfo-10.19-4.22.1.x86_64.rpmLinux
SUSE-SU-2021:3761-1(SUSE Linux Enterprise Server 12-SP5 ) postgresql10-debuginfo-10.19-4.22.1.x86_64.rpmLinux
SUSE-SU-2021:3761-1(SUSE Linux Enterprise Server 12-SP5 ) postgresql10-debugsource-10.19-4.22.1.x86_64.rpmLinux
SUSE-SU-2021:3761-1(SUSE Linux Enterprise Server 12-SP5 ) postgresql10-docs-10.19-4.22.1.noarch.rpmLinux
SUSE-SU-2021:3761-1(SUSE Linux Enterprise Server 12-SP5 ) postgresql10-plperl-10.19-4.22.1.x86_64.rpmLinux
SUSE-SU-2021:3761-1(SUSE Linux Enterprise Server 12-SP5 ) postgresql10-plperl-debuginfo-10.19-4.22.1.x86_64.rpmLinux
SUSE-SU-2021:3761-1(SUSE Linux Enterprise Server 12-SP5 ) postgresql10-plpython-10.19-4.22.1.x86_64.rpmLinux
SUSE-SU-2021:3761-1(SUSE Linux Enterprise Server 12-SP5 ) postgresql10-plpython-debuginfo-10.19-4.22.1.x86_64.rpmLinux
SUSE-SU-2021:3761-1(SUSE Linux Enterprise Server 12-SP5 ) postgresql10-pltcl-10.19-4.22.1.x86_64.rpmLinux
SUSE-SU-2021:3761-1(SUSE Linux Enterprise Server 12-SP5 ) postgresql10-pltcl-debuginfo-10.19-4.22.1.x86_64.rpmLinux
SUSE-SU-2021:3761-1(SUSE Linux Enterprise Server 12-SP5 ) postgresql10-server-10.19-4.22.1.x86_64.rpmLinux
SUSE-SU-2021:3761-1(SUSE Linux Enterprise Server 12-SP5 ) postgresql10-server-debuginfo-10.19-4.22.1.x86_64.rpmLinux
(RHSA-2022:1891) libpq security update libpq-debugsource-13.5-1.el8.i686.rpmLinux
(RHSA-2022:1891) libpq security update libpq-debugsource-13.5-1.el8.x86_64.rpmLinux
libpq security update (RLSA-2022:1891) libpq-13.5-1.el8.i686.rpmLinux
libpq security update (RLSA-2022:1891) libpq-13.5-1.el8.x86_64.rpmLinux
libpq security update (RLSA-2022:1891) libpq-devel-13.5-1.el8.i686.rpmLinux
libpq security update (RLSA-2022:1891) libpq-devel-13.5-1.el8.x86_64.rpmLinux
Vulnerabilities CVE-2021-23222 Announcement,CVE-2021-23214 Announcement are fixed in Postgresql 14.1 (For Linux)Linux
Vulnerabilities CVE-2021-23222,CVE-2021-23214 are fixed in PostgreSQL 14.1 (For Linux)Linux
Vulnerabilities CVE-2021-23222,CVE-2021-23214 are fixed in PostgreSQL 13.5 (For Linux)Linux
Vulnerabilities CVE-2021-23222,CVE-2021-23214 are fixed in PostgreSQL 12.9 (For Linux)Linux
Vulnerabilities CVE-2021-23222,CVE-2021-23214 are fixed in PostgreSQL 11.14 (For Linux)Linux
Vulnerabilities CVE-2021-23222,CVE-2021-23214 are fixed in PostgreSQL 10.19 (For Linux)Linux
Vulnerabilities CVE-2021-23222,CVE-2021-23214 are fixed in PostgreSQL 9.6.24 (For Linux)Linux

Patch Details

No records found

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234