Odyssey passes to server unencrypted bytes from man-in-the-middle When Odyssey is configured to use certificate Common Name for client authentication, a man-in-the-middle attacker can inject arbitrary SQL queries when a connection is first established, despite the use of SSL certificate verification and encryption. This is similar to CVE-2021-23214 for PostgreSQL.
References
Configurations
History
21 Nov 2024, 06:29
Type | Values Removed | Values Added |
---|---|---|
References | () https://github.com/yandex/odyssey/issues/376%2C - | |
References | () https://www.postgresql.org/support/security/CVE-2021-23214/ - Not Applicable |
14 Oct 2022, 18:37
Type | Values Removed | Values Added |
---|---|---|
CPE | cpe:2.3:a:postgresql:postgresql:*:*:*:*:*:*:*:* |
cpe:2.3:a:odyssey_project:odyssey:1.1:*:*:*:*:*:*:* |
References | (MISC) https://www.postgresql.org/support/security/CVE-2021-23214/ - Not Applicable |
31 Aug 2022, 16:54
Type | Values Removed | Values Added |
---|---|---|
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 8.1 |
CPE | cpe:2.3:a:postgresql:postgresql:14.0:*:*:*:*:*:*:* cpe:2.3:a:postgresql:postgresql:*:*:*:*:*:*:*:* |
|
CWE | CWE-295 | |
References | (MISC) https://github.com/yandex/odyssey/issues/376, - Broken Link | |
References | (MISC) https://www.postgresql.org/support/security/CVE-2021-23214/ - Vendor Advisory |
25 Aug 2022, 18:46
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2022-08-25 18:15
Updated : 2024-11-21 06:29
NVD link : CVE-2021-43766
Mitre link : CVE-2021-43766
CVE.ORG link : CVE-2021-43766
JSON object : View
Products Affected
odyssey_project
- odyssey