Loading HuntDB...

GHSA-467w-rrqc-395f

GitHub Security Advisory

⚠ Unreviewed HIGH Has CVE

Advisory Details

When the server is configured to use trust authentication with a clientcert requirement or to use cert authentication, a man-in-the-middle attacker can inject arbitrary SQL queries when a connection is first established, despite the use of SSL certificate verification and encryption.

Related CVEs

Key Information

GHSA ID
GHSA-467w-rrqc-395f
Published
March 5, 2022 12:00 AM
Last Modified
March 17, 2022 12:03 AM
CVSS Score
7.5 /10
Primary Ecosystem
Unknown
Primary Package
Unknown
GitHub Reviewed
✗ No

Dataset

Last updated: September 20, 2025 6:29 AM

Data from GitHub Advisory Database. This information is provided for research and educational purposes.