CVE-2021-43767

CVE-2021-43767

Odyssey passes to client unencrypted bytes from man-in-the-middle When Odyssey storage is configured to use the PostgreSQL server using ‘trust’ authentication with a ‘clientcert’ requirement or to use ‘cert’ authentication, a man-in-the-middle attacker can inject false responses to the client’s first few queries. Despite the use of SSL certificate verification and encryption, Odyssey will pass these results to client as if they originated from valid server. This is similar to CVE-2021-23222 for PostgreSQL.

Source: CVE-2021-43767

답글 남기기

이메일 주소는 공개되지 않습니다. 필수 필드는 *로 표시됩니다