MEDIUM 5.9 Microsoft
CVE-2021-43767
Odyssey passes to client unencrypted bytes from man-in-the-middle When Odyssey storage is configured to use the PostgreSQL server using 'trust' authentication with a 'clientcert' requirement or to use 'cert' authentication a man-in-the-middle attacker can inject false responses to the client's first few queries. Despite the use of SSL certificate verification and encryption Odyssey will pass these results to client as if they originated from valid server. This is similar to CVE-2021-23222 for PostgreSQL.
Microsoft Security Update 2022-Aug: Odyssey passes to client unencrypted bytes from man-in-the-middle When Odyssey storage is configured to use the PostgreSQL server using 'trust' authentication with a 'clientcert' requirement or to use 'cert' authentication a man-in-the-middle attacker can inject false responses to the client's first few queries. Despite the use of SSL certificate verification and encryption Odyssey will pass these results to client as if they originated from valid server. This is similar to CVE-2021-23222 for PostgreSQL.
Affected Products
- cm1 postgresql 12.12-1 on CBL Mariner 1.0
References
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-43767
- https://nvd.nist.gov/vuln/detail/CVE-2021-43767
This medium severity vulnerability with a CVSS score of 5.9 was published on 2022-08-09 via Microsoft. Affected: cm1 postgresql 12.12-1 on CBL Mariner 1.0.
vulnfeed aggregates 9119 vulnerabilities from NVD, CISA KEV,
Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.