Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2021-43767


Odyssey passes to client unencrypted bytes from man-in-the-middle When Odyssey storage is configured to use the PostgreSQL server using 'trust' authentication with a 'clientcert' requirement or to use 'cert' authentication, a man-in-the-middle attacker can inject false responses to the client's first few queries. Despite the use of SSL certificate verification and encryption, Odyssey will pass these results to client as if they originated from valid server. This is similar to CVE-2021-23222 for PostgreSQL.


Published

2022-08-25T18:15:09.377

Last Modified

2024-11-21T06:29:45.000

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 5.9 (MEDIUM)

Weaknesses
  • Type: Secondary
    CWE-522
  • Type: Primary
    CWE-295

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application postgresql postgresql < 9.6.24 Yes
Application postgresql postgresql < 10.19 Yes
Application postgresql postgresql < 11.14 Yes
Application postgresql postgresql < 12.9 Yes
Application postgresql postgresql < 13.5 Yes
Application postgresql postgresql 14.0 Yes

References