← Back

CVE-2021-43767

nvd nist
Published: Aug 25, 2022Modified: Nov 21, 2024

JSON object

Loading...
5.9
Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N
Exploitability: 2.2 / Impact: 3.6
Source: NVD

Description

Odyssey passes to client unencrypted bytes from man-in-the-middle When Odyssey storage is configured to use the PostgreSQL server using 'trust' authentication with a 'clientcert' requirement or to use 'cert' authentication, a man-in-the-middle attacker can inject false responses to the client's first few queries. Despite the use of SSL certificate verification and encryption, Odyssey will pass these results to client as if they originated from valid server. This is similar to CVE-2021-23222 for PostgreSQL.

Affected (6)

1 product
Postgresql
Configuration A
6 vulnerable
Vulnerable SoftwareAffected Versions
Postgresql
From 10.0 to 10.19
From 11.0 to 11.14
From 12.0 to 12.9
From 13.0 to 13.5
From 9.6.0 to 9.6.24
Version 14.0

References (4)

Source: patrick@puiterwijk.org
Not ApplicableVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Not ApplicableVendor Advisory

Timeline

No history available yet.