{"id":"CVE-2021-43766","details":"Odyssey passes to server unencrypted bytes from man-in-the-middle When Odyssey is configured to use certificate Common Name for client authentication, a man-in-the-middle attacker can inject arbitrary SQL queries when a connection is first established, despite the use of SSL certificate verification and encryption. This is similar to CVE-2021-23214 for PostgreSQL.","modified":"2026-07-09T03:25:19.871336Z","published":"2022-08-25T18:15:09.317Z","references":[{"type":"WEB","url":"https://www.postgresql.org/support/security/CVE-2021-23214/"},{"type":"REPORT","url":"https://github.com/yandex/odyssey/issues/376%2C"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/yandex/odyssey","events":[{"introduced":"b7bcb86956fe86a7d6b53ddb7318dca77bf01ed0"},{"last_affected":"b7bcb86956fe86a7d6b53ddb7318dca77bf01ed0"}],"database_specific":{"source":"CPE_STRING","cpe":"cpe:2.3:a:odyssey_project:odyssey:1.1:*:*:*:*:*:*:*","extracted_events":[{"introduced":"1.1"},{"last_affected":"1.1"}]}}],"versions":["1.1"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2021-43766.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H"}]}