CVE-2021-23222
Public on 2022-03-02
Modified on 2023-09-20
Description
A man-in-the-middle attacker can inject false responses to the client's first few queries, despite the use of SSL certificate verification and encryption.
Severity
CVSS v3 Base Score
See breakdown
Affected Packages
Platform | Package | Release Date | Advisory | Status |
---|---|---|---|---|
HAQM Linux 2 - Postgresql12 Extra | libpq | 2023-08-07 | ALAS2POSTGRESQL12-2023-003 | Fixed |
HAQM Linux 2 - Postgresql14 Extra | libpq | 2024-02-29 | ALAS2POSTGRESQL14-2024-009 | Fixed |
HAQM Linux 2023 | libpq | Not Affected | ||
HAQM Linux 2 - Postgresql12 Extra | postgresql | 2023-08-07 | ALAS2POSTGRESQL12-2023-002 | Fixed |
HAQM Linux 2 - Postgresql13 Extra | postgresql | 2023-08-07 | ALAS2POSTGRESQL13-2023-002 | Fixed |
HAQM Linux 2 - Postgresql14 Extra | postgresql | 2024-02-29 | ALAS2POSTGRESQL14-2024-008 | Fixed |
HAQM Linux 1 | postgresql92 | Not Affected |
CVSS Scores
Score Type | Score | Vector | |
---|---|---|---|
HAQM Linux | CVSSv3 | 5.9 | CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N |
NVD | CVSSv2 | 4.3 | AV:N/AC:M/Au:N/C:P/I:N/A:N |
NVD | CVSSv3 | 5.9 | CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N |