{"id":"GHSA-9cfh-vx93-84vv","summary":"PostgresNIO processes unencrypted bytes from man-in-the-middle","details":"### Impact\nAny user of PostgresNIO connecting to servers with TLS enabled is vulnerable to a man-in-the-middle attacker injecting false responses to the client's first few queries, despite the use of TLS certificate verification and encryption.\n\n_The remaining text in this section is quoted verbatim from [PostgreSQL's CVE-2021-23222 advisory](https://www.postgresql.org/support/security/CVE-2021-23222/):_\n\n\u003e If more preconditions hold, the attacker can exfiltrate the client's password or other confidential data that might be transmitted early in a session. The attacker must have a way to trick the client's intended server into making the confidential data accessible to the attacker. A known implementation having that property is a PostgreSQL configuration vulnerable to [CVE-2021-23214](https://www.postgresql.org/support/security/CVE-2021-23214/). As with any exploitation of [CVE-2021-23214](https://www.postgresql.org/support/security/CVE-2021-23214/), the server must be using trust authentication with a clientcert requirement or using cert authentication. To disclose a password, the client must be in possession of a password, which is atypical when using an authentication configuration vulnerable to [CVE-2021-23214](https://www.postgresql.org/support/security/CVE-2021-23214/). The attacker must have some other way to access the server to retrieve the exfiltrated data (a valid, unprivileged login account would be sufficient).\n\n### Patches\nThe vulnerability is addressed in PostgresNIO versions starting from [1.14.2](https://github.com/vapor/postgres-nio/releases/tag/1.14.2) via [2df54bc94607f44584ae6ffa74e3cd754fffafc7](https://github.com/vapor/postgres-nio/commit/2df54bc94607f44584ae6ffa74e3cd754fffafc7), which required [additional support](https://github.com/apple/swift-nio/pull/2419) from SwiftNIO.\n\n### Workarounds\nThere are no known workarounds for unpatched users.\n\n### Additional Credits\nSpecial thanks to PostgreSQL's Tom Lane \u003c[tgl@sss.pgh.pa.us](mailto:tgl@sss.pgh.pa.us)\u003e for reporting this issue!\n\n### References\n- [PostgreSQL security advisory for CVE-2021-23222](https://www.postgresql.org/support/security/CVE-2021-23222/)\n- [GitHub security advisory GHSA-735f-7qx4-jqq5 for CVE-2021-23222](https://github.com/advisories/GHSA-735f-7qx4-jqq5)\n- [PostgreSQL security advisory for CVE-2021-23214](https://www.postgresql.org/support/security/CVE-2021-23214/)\n- [GitHub security advisory GHSA-467w-rrqc-395f for CVE-2021-23214](https://github.com/advisories/GHSA-467w-rrqc-395f)\n- [SwiftNIO PR #2419 Add unprocessedBytes property on NIOSingleStepByteToMessageProcessor](https://github.com/apple/swift-nio/pull/2419)\n- [PostgresNIO commit 2df54bc94607f44584ae6ffa74e3cd754fffafc7](https://github.com/vapor/postgres-nio/commit/2df54bc94607f44584ae6ffa74e3cd754fffafc7)\n- [PostgresNIO 1.42.2 release](https://github.com/vapor/postgres-nio/releases/tag/1.14.2)","aliases":["CVE-2023-31136"],"modified":"2026-02-04T03:00:05.535913Z","published":"2023-05-10T19:20:16Z","related":["CVE-2023-31136"],"database_specific":{"cwe_ids":["CWE-522"],"github_reviewed_at":"2023-05-10T19:20:16Z","github_reviewed":true,"nvd_published_at":"2023-05-09T14:15:13Z","severity":"LOW"},"references":[{"type":"WEB","url":"https://github.com/vapor/postgres-nio/security/advisories/GHSA-9cfh-vx93-84vv"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2023-31136"},{"type":"WEB","url":"https://github.com/apple/swift-nio/pull/2419"},{"type":"WEB","url":"https://github.com/vapor/postgres-nio/commit/2df54bc94607f44584ae6ffa74e3cd754fffafc7"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-467w-rrqc-395f"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-735f-7qx4-jqq5"},{"type":"PACKAGE","url":"https://github.com/vapor/postgres-nio"},{"type":"WEB","url":"https://github.com/vapor/postgres-nio/releases/tag/1.14.2"},{"type":"WEB","url":"https://www.postgresql.org/support/security/CVE-2021-23214"},{"type":"WEB","url":"https://www.postgresql.org/support/security/CVE-2021-23222"}],"affected":[{"package":{"name":"github.com/vapor/postgres-nio","ecosystem":"SwiftURL","purl":"pkg:swift/github.com/vapor/postgres-nio"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"1.14.2"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2023/05/GHSA-9cfh-vx93-84vv/GHSA-9cfh-vx93-84vv.json"}}],"schema_version":"1.7.3","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N"}]}