CVE-2021-23214

All FrameworksPostgreSQLCWE-89CVE-2021-23214

CVE-2021-23214

State: PUBLISHED · Published: 2022-03-04 · Updated: 2024-08-03 · Assigner: redhat
Description
When the server is configured to use trust authentication with a clientcert requirement or to use cert authentication, a man-in-the-middle attacker can inject arbitrary SQL queries when a connection is first established, despite the use of SSL certificate verification and encryption.
CWE
Affected
CVSS
References
Source
cvelistV5-main/cves/2021/23xxx/CVE-2021-23214.json