CVE-2021-23214
When the server is configured to use trust authentication with a clientcert requirement or to use cert authentication, a man-in-the-middle attacker can inject arbitrary SQL queries when a connection is first established, despite the use of SSL certificate verification and encryption. This is similar to CVE-2011-0411 (different product). The PostgreSQL project thanks Jacob Champion for reporting this problem.
Version Information
| Affected branch | Introduced | Fixed In | Fix Published |
|---|---|---|---|
| 10 | — | 10.19 | 2021-11-11 |
| 11 | — | 11.14 | 2021-11-11 |
| 12 | — | 12.9 | 2021-11-11 |
| 13 | — | 13.5 | 2021-11-11 |
| 14 | — | 14.1 | 2021-11-11 |
| 9.6 | — | 9.6.24 | 2021-11-11 |
CVSS 3.0
| Overall Score | 8.1 |
|---|---|
| Component | core server |
| Vector | AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H |
First published: 2021-11-11
Historical source observations
These dated records preserve the original source claims separately from the reviewed fix list.
center · 2026-10-03 12:08:35.169032+08
- PostgreSQL 14 · Original minor coordinate: 1
pgweb · 2026-10-03 12:08:55.967155+08
- PostgreSQL 14 · Original minor coordinate: 1