mirror of
https://github.com/fkie-cad/nvd-json-data-feeds.git
synced 2025-05-29 17:51:17 +00:00
96 lines
2.9 KiB
JSON
96 lines
2.9 KiB
JSON
![]() |
{
|
||
|
"id": "CVE-2021-43766",
|
||
|
"sourceIdentifier": "patrick@puiterwijk.org",
|
||
|
"published": "2022-08-25T18:15:09.317",
|
||
|
"lastModified": "2022-12-21T15:01:19.963",
|
||
|
"vulnStatus": "Analyzed",
|
||
|
"descriptions": [
|
||
|
{
|
||
|
"lang": "en",
|
||
|
"value": "Odyssey passes to server unencrypted bytes from man-in-the-middle When Odyssey is configured to use certificate Common Name for client authentication, a man-in-the-middle attacker can inject arbitrary SQL queries when a connection is first established, despite the use of SSL certificate verification and encryption. This is similar to CVE-2021-23214 for PostgreSQL."
|
||
|
},
|
||
|
{
|
||
|
"lang": "es",
|
||
|
"value": "Odyssey pasa al servidor bytes sin cifrar desde el hombre en el medio Cuando Odyssey est\u00e1 configurado para usar el certificado Nombre Com\u00fan para la autenticaci\u00f3n del cliente, un atacante hombre en el medio puede inyectar consultas SQL arbitrarias cuando es establecida una conexi\u00f3n por primera vez, a pesar del uso de la verificaci\u00f3n y el cifrado del certificado SSL. Esto es similar a CVE-2021-23214 para PostgreSQL."
|
||
|
}
|
||
|
],
|
||
|
"metrics": {
|
||
|
"cvssMetricV31": [
|
||
|
{
|
||
|
"source": "nvd@nist.gov",
|
||
|
"type": "Primary",
|
||
|
"cvssData": {
|
||
|
"version": "3.1",
|
||
|
"vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H",
|
||
|
"attackVector": "NETWORK",
|
||
|
"attackComplexity": "HIGH",
|
||
|
"privilegesRequired": "NONE",
|
||
|
"userInteraction": "NONE",
|
||
|
"scope": "UNCHANGED",
|
||
|
"confidentialityImpact": "HIGH",
|
||
|
"integrityImpact": "HIGH",
|
||
|
"availabilityImpact": "HIGH",
|
||
|
"baseScore": 8.1,
|
||
|
"baseSeverity": "HIGH"
|
||
|
},
|
||
|
"exploitabilityScore": 2.2,
|
||
|
"impactScore": 5.9
|
||
|
}
|
||
|
]
|
||
|
},
|
||
|
"weaknesses": [
|
||
|
{
|
||
|
"source": "nvd@nist.gov",
|
||
|
"type": "Primary",
|
||
|
"description": [
|
||
|
{
|
||
|
"lang": "en",
|
||
|
"value": "CWE-295"
|
||
|
}
|
||
|
]
|
||
|
},
|
||
|
{
|
||
|
"source": "patrick@puiterwijk.org",
|
||
|
"type": "Secondary",
|
||
|
"description": [
|
||
|
{
|
||
|
"lang": "en",
|
||
|
"value": "CWE-89"
|
||
|
}
|
||
|
]
|
||
|
}
|
||
|
],
|
||
|
"configurations": [
|
||
|
{
|
||
|
"nodes": [
|
||
|
{
|
||
|
"operator": "OR",
|
||
|
"negate": false,
|
||
|
"cpeMatch": [
|
||
|
{
|
||
|
"vulnerable": true,
|
||
|
"criteria": "cpe:2.3:a:odyssey_project:odyssey:1.1:*:*:*:*:*:*:*",
|
||
|
"matchCriteriaId": "34DBBE36-E704-416B-B8C1-CCF6D8F2B865"
|
||
|
}
|
||
|
]
|
||
|
}
|
||
|
]
|
||
|
}
|
||
|
],
|
||
|
"references": [
|
||
|
{
|
||
|
"url": "https://github.com/yandex/odyssey/issues/376,",
|
||
|
"source": "patrick@puiterwijk.org",
|
||
|
"tags": [
|
||
|
"Broken Link"
|
||
|
]
|
||
|
},
|
||
|
{
|
||
|
"url": "https://www.postgresql.org/support/security/CVE-2021-23214/",
|
||
|
"source": "patrick@puiterwijk.org",
|
||
|
"tags": [
|
||
|
"Not Applicable"
|
||
|
]
|
||
|
}
|
||
|
]
|
||
|
}
|