PostgresNIO is a Swift client for PostgreSQL. Any user of PostgresNIO prior to version 1.14.2 connecting to servers with TLS enabled is vulnerable to a man-in-the-middle attacker injecting false responses to the client's first few queries, despite the use of TLS certificate verification and encryption. The vulnerability is addressed in PostgresNIO versions starting from 1.14.2. There are no known workarounds for unpatched users.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: GitHub_M
Published: 2023-05-09T13:37:38.193Z
Updated: 2024-08-02T14:45:25.783Z
Reserved: 2023-04-24T21:44:10.417Z
Link: CVE-2023-31136
Vulnrichment
No data.
NVD
Status : Modified
Published: 2023-05-09T14:15:13.520
Modified: 2024-11-21T08:01:28.043
Link: CVE-2023-31136
Redhat
No data.