CVE-2021-23222
Public on 2022-03-02
Modified on 2023-09-20
Description
A man-in-the-middle attacker can inject false responses to the client's first few queries, despite the use of SSL certificate verification and encryption.
Severity
CVSS v3 Base Score
See breakdown
Affected Packages
Platform | Package | Release Date | Advisory | Status |
---|---|---|---|---|
Amazon Linux 2 - Postgresql12 Extra | libpq | 2023-08-07 | ALAS2POSTGRESQL12-2023-003 | Fixed |
Amazon Linux 2 - Postgresql14 Extra | libpq | 2024-02-29 | ALAS2POSTGRESQL14-2024-009 | Fixed |
Amazon Linux 2023 | libpq | Not Affected | ||
Amazon Linux 2 - Postgresql12 Extra | postgresql | 2023-08-07 | ALAS2POSTGRESQL12-2023-002 | Fixed |
Amazon Linux 2 - Postgresql13 Extra | postgresql | 2023-08-07 | ALAS2POSTGRESQL13-2023-002 | Fixed |
Amazon Linux 2 - Postgresql14 Extra | postgresql | 2024-02-29 | ALAS2POSTGRESQL14-2024-008 | Fixed |
Amazon Linux 1 | postgresql92 | Not Affected |
CVSS Scores
Score Type | Score | Vector | |
---|---|---|---|
Amazon Linux | CVSSv3 | 5.9 | CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N |
NVD | CVSSv2 | 4.3 | AV:N/AC:M/Au:N/C:P/I:N/A:N |
NVD | CVSSv3 | 5.9 | CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N |