Lucene search

K
ubuntucveUbuntu.comUB:CVE-2021-23222
HistoryNov 11, 2021 - 12:00 a.m.

CVE-2021-23222

2021-11-1100:00:00
ubuntu.com
ubuntu.com
22

4.3 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:M/Au:N/C:P/I:N/A:N

5.9 Medium

CVSS3

Attack Vector

NETWORK

Attack Complexity

HIGH

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N

0.001 Low

EPSS

Percentile

43.7%

A man-in-the-middle attacker can inject false responses to the client’s
first few queries, despite the use of SSL certificate verification and
encryption.

Notes

Author Note
leosilva PostgreSQL 9.3 is end of life upstream, and no updates are are available. Marking as deferred in -esm-main releases.
mdeslaur Plan is for postgresql-13 to be removed from jammy, marking as deferred for now.
OSVersionArchitecturePackageVersionFilename
ubuntu18.04noarchpostgresql-10< 10.19-0ubuntu0.18.04.1UNKNOWN
ubuntu20.04noarchpostgresql-12< 12.9-0ubuntu0.20.04.1UNKNOWN
ubuntu21.04noarchpostgresql-13< 13.5-0ubuntu0.21.04.1UNKNOWN
ubuntu21.10noarchpostgresql-13< 13.5-0ubuntu0.21.10.1UNKNOWN
ubuntu14.04noarchpostgresql-9.3< anyUNKNOWN
ubuntu16.04noarchpostgresql-9.5< 9.5.25-0ubuntu0.16.04.1+esm3UNKNOWN

4.3 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:M/Au:N/C:P/I:N/A:N

5.9 Medium

CVSS3

Attack Vector

NETWORK

Attack Complexity

HIGH

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N

0.001 Low

EPSS

Percentile

43.7%