CVE-2023-31136
Any user of PostgresNIO prior to version 1.14.2 connecting to servers with TLS enabled is vulnerable to a man-in-the-middle attacker injecting false responses to the client's first few queries, despite the use of TLS certificate verification and…
Does this matter?
Lower severity and a low EPSS score (0.49%). Track it; it rarely justifies an emergency change on its own.
Description
PostgresNIO is a Swift client for PostgreSQL. Any user of PostgresNIO prior to version 1.14.2 connecting to servers with TLS enabled is vulnerable to a man-in-the-middle attacker injecting false responses to the client's first few queries, despite the use of TLS certificate verification and encryption. The vulnerability is addressed in PostgresNIO versions starting from 1.14.2. There are no known workarounds for unpatched users.
- CVSS 3.1
- 5.9 MEDIUMCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
- EPSS
- 0.49% probability · 41th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-522
- Affected
- vapor/postgresnio
- Source
- security-advisories@github.com
References
- https://github.com/advisories/GHSA-467w-rrqc-395fNot Applicable
- https://github.com/advisories/GHSA-735f-7qx4-jqq5Not Applicable
- https://github.com/apple/swift-nio/pull/2419Patch
- https://github.com/vapor/postgres-nio/commit/2df54bc94607f44584ae6ffa74e3cd754fffafc7Patch
- https://github.com/vapor/postgres-nio/releases/tag/1.14.2Release Notes
- https://github.com/vapor/postgres-nio/security/advisories/GHSA-9cfh-vx93-84vvVendor Advisory
- https://www.postgresql.org/support/security/CVE-2021-23214/Not Applicable
- https://www.postgresql.org/support/security/CVE-2021-23222/Not Applicable
- https://github.com/advisories/GHSA-467w-rrqc-395fNot Applicable
- https://github.com/advisories/GHSA-735f-7qx4-jqq5Not Applicable
- https://github.com/apple/swift-nio/pull/2419Patch
- https://github.com/vapor/postgres-nio/commit/2df54bc94607f44584ae6ffa74e3cd754fffafc7Patch
- https://github.com/vapor/postgres-nio/releases/tag/1.14.2Release Notes
- https://github.com/vapor/postgres-nio/security/advisories/GHSA-9cfh-vx93-84vvVendor Advisory
- https://www.postgresql.org/support/security/CVE-2021-23214/Not Applicable
- https://www.postgresql.org/support/security/CVE-2021-23222/Not Applicable
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.