CVE detail
CVE-2021-23214 — CVE-2021-23214
Published 2022-03-04 · Modified 2026-06-17 · Vendor postgresql · Product postgresql · Source nvd
HIGH
severity
CVSS-derived band
0.0190
EPSS probability
exploitation probability, 30d
78.0%
EPSS percentile
percentile vs all CVEs
NOT LISTED
CISA KEV
known exploited catalog
Description
When the server is configured to use trust authentication with a clientcert requirement or to use cert authentication, a man-in-the-middle attacker can inject arbitrary SQL queries when a connection is first established, despite the use of SSL certificate verification and encryption.
Remediation
No vendor-published fix data in our corpus for this CVE. Check the references below or the vendor's PSIRT / security advisories page.
References