CVE Vulnerabilities

CVE-2021-23222

Insufficiently Protected Credentials

Published: Mar 02, 2022 | Modified: Nov 21, 2024
CVSS 3.x
5.9
MEDIUM
Source:
NVD
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
CVSS 2.x
4.3 MEDIUM
AV:N/AC:M/Au:N/C:P/I:N/A:N
RedHat/V2
RedHat/V3
3.7 LOW
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

A man-in-the-middle attacker can inject false responses to the clients first few queries, despite the use of SSL certificate verification and encryption.

Weakness

The product transmits or stores authentication credentials, but it uses an insecure method that is susceptible to unauthorized interception and/or retrieval.

Affected Software

NameVendorStart VersionEnd Version
PostgresqlPostgresql9.6 (including)9.6.24 (excluding)
PostgresqlPostgresql10.0 (including)10.19 (excluding)
PostgresqlPostgresql11.0 (including)11.14 (excluding)
PostgresqlPostgresql12.0 (including)12.9 (excluding)
PostgresqlPostgresql13.0 (including)13.5 (excluding)
PostgresqlPostgresql14.0 (including)14.0 (including)
Red Hat Enterprise Linux 8RedHatlibpq-0:13.5-1.el8*
Red Hat Software Collections for Red Hat Enterprise Linux 7RedHatrh-postgresql13-postgresql-0:13.5-1.el7*
Red Hat Software Collections for Red Hat Enterprise Linux 7RedHatrh-postgresql12-postgresql-0:12.9-1.el7*
Postgresql-10Ubuntubionic*
Postgresql-10Ubuntuesm-infra/bionic*
Postgresql-10Ubuntuupstream*
Postgresql-12Ubuntuesm-infra/focal*
Postgresql-12Ubuntufocal*
Postgresql-12Ubuntutrusty*
Postgresql-12Ubuntuupstream*
Postgresql-13Ubuntuhirsute*
Postgresql-13Ubuntuimpish*
Postgresql-13Ubuntuupstream*
Postgresql-9.1Ubuntutrusty*
Postgresql-9.3Ubuntutrusty*
Postgresql-9.3Ubuntutrusty/esm*
Postgresql-9.3Ubuntuupstream*
Postgresql-9.5Ubuntuesm-infra/xenial*
Postgresql-9.5Ubuntuupstream*
Postgresql-9.5Ubuntuxenial*

Potential Mitigations

References