Improper Enforcement of Message Integrity During Transmission in a Communication Channel Affecting github.com/vapor/postgres-nio package, versions <1.14.2
Threat Intelligence
EPSS
0.27% (69th
percentile)
Do your applications use this vulnerable package?
In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applications- Snyk ID SNYK-SWIFT-VAPORPOSTGRESNIO-5507294
- published 10 May 2023
- disclosed 9 May 2023
- credit fabianfett, gwynne
Introduced: 9 May 2023
CVE-2023-31136 Open this link in a new tabHow to fix?
Upgrade vapor/postgres-nio
to version 1.14.2 or higher.
Overview
Affected versions of this package are vulnerable to Improper Enforcement of Message Integrity During Transmission in a Communication Channel when the connection to servers with TLS enabled, a man-in-the-middle attacker can inject false responses to the client's first few queries. Exploiting this vulnerability is possible despite the use of TLS certificate verification and encryption.
References
CVSS Scores
version 3.1