Vulnerabilities > CVE-2021-23214

047910
CVSS 8.1 - HIGH
Attack vector
NETWORK
Attack complexity
HIGH
Privileges required
NONE
Confidentiality impact
HIGH
Integrity impact
HIGH
Availability impact
HIGH
network
high complexity
postgresql
fedoraproject
redhat

Summary

When the server is configured to use trust authentication with a clientcert requirement or to use cert authentication, a man-in-the-middle attacker can inject arbitrary SQL queries when a connection is first established, despite the use of SSL certificate verification and encryption.

Vulnerable Configurations

Part Description Count
Application
Postgresql
455
Application
Redhat
1
OS
Fedoraproject
2
OS
Redhat
3