A man-in-the-middle attacker can inject false responses to the client's first few queries, despite the use of SSL certificate verification and encryption.
[
{
"id": "CVE-2021-23222-e1be026c",
"digest": {
"line_hashes": [
"10037443517696866748761392046871582022",
"325675312630126864791861414191520860108",
"248756423465337085234785710824740055381",
"219130724463359041405235398817575440371",
"18312600838351471896985731433715124179",
"29813103265162816138856506205737681509",
"248756423465337085234785710824740055381",
"219130724463359041405235398817575440371"
],
"threshold": 0.9
},
"signature_version": "v1",
"target": {
"file": "src/interfaces/libpq/fe-connect.c"
},
"deprecated": false,
"signature_type": "Line",
"source": "https://github.com/postgres/postgres/commit/160c0258802d10b0600d7671b1bbea55d8e17d45"
},
{
"id": "CVE-2021-23222-f5ed594b",
"digest": {
"length": 22472.0,
"function_hash": "218920273742902448943626208937972612244"
},
"signature_version": "v1",
"target": {
"file": "src/interfaces/libpq/fe-connect.c",
"function": "PQconnectPoll"
},
"deprecated": false,
"signature_type": "Function",
"source": "https://github.com/postgres/postgres/commit/160c0258802d10b0600d7671b1bbea55d8e17d45"
}
]