{"id":"CVE-2021-23214","year":2021,"sequence":23214,"component":"core server","score":8.1,"cvss_version":"3.0","vector":"AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","first_published":"2021-11-11","source_url":"https://www.postgresql.org/support/security/CVE-2021-23214/","facts":{"affected":{"10":"10","11":"11","12":"12","13":"13","14":"14","9.6":"9.6"},"component":"core server","cvss_version":"3.0","description_en":"When the server is configured to use trust authentication with a clientcert requirement or to use cert authentication, a man-in-the-middle attacker can inject arbitrary SQL queries when a connection is first established, despite the use of SSL certificate verification and encryption. This is similar to CVE-2011-0411 (different product).\n\nThe PostgreSQL project thanks Jacob Champion for reporting this problem.","first_published":"2021-11-11","fixed":{"10":"10.19","11":"11.14","12":"12.9","13":"13.5","14":"14.1","9.6":"9.6.24"},"id":"CVE-2021-23214","introduced":{},"published":{"10":"2021-11-11","11":"2021-11-11","12":"2021-11-11","13":"2021-11-11","14":"2021-11-11","9.6":"2021-11-11"},"score":8.1,"title":"Server processes unencrypted bytes from man-in-the-middle","url":"https://www.postgresql.org/support/security/CVE-2021-23214/","vector":"AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H"},"reviewed_hash":"6a65a7884245936f6adaef8709d290d460e999dfce1ad78734fa7c9a324ed325","source_hash":"965b9e2323feab543f3cbeb74c418c3a5b43cbefc6594d2862ff0d24dcf8e6a2","text":{"locale":"zh-Hans","title":"服务器会处理中间人发送的未加密字节","description":"服务器会处理中间人发送的未加密字节","details":null,"format":"markdown","provenance":{"identity":"immutable_cve_code","sources":[{"observed_at":"2026-10-03 12:08:35.169032+08","raw":{"component":"core server","cve":"2021-23214","cvenumber":202123214,"description":"服务器会处理中间人发送的未加密字节","details":null,"detailslink":"https://access.redhat.com/security/cve/CVE-2021-23214","id":31,"legacyscore":"","newspost_id":null,"public":true,"vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H"},"source":"center","source_id":31,"source_table_sha256":"b57ee28b2263464208af0ccf7512b31f0c1ab7140d12dda09a0c87de341f1372"},{"observed_at":"2026-10-03 12:08:55.967155+08","raw":{"component":"core server","cve":"2021-23214","cvenumber":202123214,"description":"服务器会处理中间人发送的未加密字节","details":null,"detailslink":"https://access.redhat.com/security/cve/CVE-2021-23214","id":31,"legacyscore":"","newspost_id":null,"public":true,"vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H"},"source":"pgweb","source_id":31,"source_table_sha256":"b57ee28b2263464208af0ccf7512b31f0c1ab7140d12dda09a0c87de341f1372"}]},"text_hash":"05a9a8f5feb5b3d119873dbe7b911a553d8290237a58d4c2a1805c5d7e52fdb2"},"locales":["en","zh-Hans"],"fixes":[{"major":"10","fixed_version":"10.19","introduced":null,"published_date":"2021-11-11","facts":{"fixed":"10.19","introduced":null,"published":"2021-11-11"}},{"major":"11","fixed_version":"11.14","introduced":null,"published_date":"2021-11-11","facts":{"fixed":"11.14","introduced":null,"published":"2021-11-11"}},{"major":"12","fixed_version":"12.9","introduced":null,"published_date":"2021-11-11","facts":{"fixed":"12.9","introduced":null,"published":"2021-11-11"}},{"major":"13","fixed_version":"13.5","introduced":null,"published_date":"2021-11-11","facts":{"fixed":"13.5","introduced":null,"published":"2021-11-11"}},{"major":"14","fixed_version":"14.1","introduced":null,"published_date":"2021-11-11","facts":{"fixed":"14.1","introduced":null,"published":"2021-11-11"}},{"major":"9.6","fixed_version":"9.6.24","introduced":null,"published_date":"2021-11-11","facts":{"fixed":"9.6.24","introduced":null,"published":"2021-11-11"}}],"legacy":[{"source":"center","source_id":31,"observed_at":"2026-10-03 12:08:35.169032+08","raw":{"id":31,"cve":"2021-23214","public":true,"vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","details":null,"component":"core server","cvenumber":202123214,"description":"服务器会处理中间人发送的未加密字节","detailslink":"https://access.redhat.com/security/cve/CVE-2021-23214","legacyscore":"","newspost_id":null},"fixes":[{"source_id":98,"source_version_id":27,"major":"14","fixed_minor":1,"raw":{"id":98,"patch_id":31,"version_id":27,"fixed_minor":1},"version_raw":{"id":27,"tree":14.0,"current":false,"docsgit":"","eoldate":"2026-11-12","reldate":"2026-08-13","testing":0,"supported":true,"docsloaded":"2026-09-27T08:10:47.078613+08:00","latestminor":24,"firstreldate":"2021-09-30"}}]},{"source":"pgweb","source_id":31,"observed_at":"2026-10-03 12:08:55.967155+08","raw":{"id":31,"cve":"2021-23214","public":true,"vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","details":null,"component":"core server","cvenumber":202123214,"description":"服务器会处理中间人发送的未加密字节","detailslink":"https://access.redhat.com/security/cve/CVE-2021-23214","legacyscore":"","newspost_id":null},"fixes":[{"source_id":98,"source_version_id":27,"major":"14","fixed_minor":1,"raw":{"id":98,"patch_id":31,"version_id":27,"fixed_minor":1},"version_raw":{"id":27,"tree":14.0,"current":false,"docsgit":"","eoldate":"2026-11-12","reldate":"2026-08-13","testing":0,"supported":true,"docsloaded":"2026-09-27T00:10:45.258078+08:00","latestminor":24,"firstreldate":"2021-09-30"}}]}]}
