When the server is configured to use trust authentication with a clientcert requirement or to use cert authentication, a man-in-the-middle attacker can inject arbitrary SQL queries when a connection is first established, despite the use of SSL certificate verification and encryption.
2022-03-04T16:15:08.293
2024-11-21T05:51:23.187
Modified
CVSSv3.1: 8.1 (HIGH)
AV:N/AC:H/Au:N/C:P/I:P/A:P
4.9
6.4
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | postgresql | postgresql | < 9.6.24 | Yes |
Application | postgresql | postgresql | < 10.19 | Yes |
Application | postgresql | postgresql | < 11.14 | Yes |
Application | postgresql | postgresql | < 12.9 | Yes |
Application | postgresql | postgresql | < 13.5 | Yes |
Application | postgresql | postgresql | 14.0 | Yes |
Operating System | fedoraproject | fedora | 34 | Yes |
Operating System | fedoraproject | fedora | 35 | Yes |
Application | redhat | software_collections | 1.0 | Yes |
Operating System | redhat | enterprise_linux | 8.0 | Yes |
Operating System | redhat | enterprise_linux_for_ibm_z_systems | 8.0 | Yes |
Operating System | redhat | enterprise_linux_for_power_little_endian | 8.0 | Yes |