CVE Database
/

CVE-2021-43766

Back to search

CVE-2021-43766

Published: Aug 25, 2022

Modified: Aug 4, 2024

PUBLISHED

Description

Odyssey passes to server unencrypted bytes from man-in-the-middle When Odyssey is configured to use certificate Common Name for client authentication, a man-in-the-middle attacker can inject arbitrary SQL queries when a connection is first established, despite the use of SSL certificate verification and encryption. This is similar to CVE-2021-23214 for PostgreSQL.

VendorProductVersions

n/a

Odyssey

affected
Odyssey 1.1

Weaknesses (CWE)

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now