A man-in-the-middle attacker can inject false responses to the client's first few queries, despite the use of SSL certificate verification and encryption.
| Software | From | Fixed in |
|---|---|---|
| postgresql / postgresql | 9.6 | 9.6.24 |
| postgresql / postgresql | 10.0 | 10.19 |
| postgresql / postgresql | 11.0 | 11.14 |
| postgresql / postgresql | 12.0 | 12.9 |
| postgresql / postgresql | 13.0 | 13.5 |
| postgresql / postgresql | 14.0 | 14.0.x |