{"resultsPerPage":1,"startIndex":0,"totalResults":1,"format":"NVD_CVE","version":"2.0","timestamp":"2026-05-03T19:07:22.393","vulnerabilities":[{"cve":{"id":"CVE-2021-43766","sourceIdentifier":"patrick@puiterwijk.org","published":"2022-08-25T18:15:09.317","lastModified":"2024-11-21T06:29:44.870","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"Odyssey passes to server unencrypted bytes from man-in-the-middle When Odyssey is configured to use certificate Common Name for client authentication, a man-in-the-middle attacker can inject arbitrary SQL queries when a connection is first established, despite the use of SSL certificate verification and encryption. This is similar to CVE-2021-23214 for PostgreSQL."},{"lang":"es","value":"Odyssey pasa al servidor bytes sin cifrar desde el hombre en el medio Cuando Odyssey está configurado para usar el certificado Nombre Común para la autenticación del cliente, un atacante hombre en el medio puede inyectar consultas SQL arbitrarias cuando es establecida una conexión por primera vez, a pesar del uso de la verificación y el cifrado del certificado SSL. Esto es similar a CVE-2021-23214 para PostgreSQL."}],"metrics":{"cvssMetricV31":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","baseScore":8.1,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":2.2,"impactScore":5.9}]},"weaknesses":[{"source":"patrick@puiterwijk.org","type":"Secondary","description":[{"lang":"en","value":"CWE-89"}]},{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-295"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:odyssey_project:odyssey:1.1:*:*:*:*:*:*:*","matchCriteriaId":"34DBBE36-E704-416B-B8C1-CCF6D8F2B865"}]}]}],"references":[{"url":"https://github.com/yandex/odyssey/issues/376%2C","source":"patrick@puiterwijk.org"},{"url":"https://www.postgresql.org/support/security/CVE-2021-23214/","source":"patrick@puiterwijk.org","tags":["Not Applicable"]},{"url":"https://github.com/yandex/odyssey/issues/376%2C","source":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://www.postgresql.org/support/security/CVE-2021-23214/","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Not Applicable"]}]}}]}