CVE-2023-31136
Estado: ModificadaMedia (5.9)—
PostgresNIO is a Swift client for PostgreSQL. Any user of PostgresNIO prior to version 1.14.2 connecting to servers with TLS enabled is vulnerable to a man-in-the-middle attacker injecting false responses to the client's first few queries, despite the use of TLS certificate verification and encryption. The vulnerability is addressed in PostgresNIO versions starting from 1.14.2. There are no known workarounds for unpatched users.
CVSS
- Versión: 3.1
- Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
- Puntuación base: 5.9
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.49%
- Percentil entre todas las CVEs puntuadas: 40
- Fecha de la puntuación: 6/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
CWE
- CWE-522
Referencias
- https://github.com/advisories/GHSA-467w-rrqc-395f
- https://github.com/advisories/GHSA-735f-7qx4-jqq5
- https://github.com/apple/swift-nio/pull/2419
- https://github.com/vapor/postgres-nio/commit/2df54bc94607f44584ae6ffa74e3cd754fffafc7
- https://github.com/vapor/postgres-nio/releases/tag/1.14.2
- https://github.com/vapor/postgres-nio/security/advisories/GHSA-9cfh-vx93-84vv
- https://www.postgresql.org/support/security/CVE-2021-23214/
- https://www.postgresql.org/support/security/CVE-2021-23222/
- https://github.com/advisories/GHSA-467w-rrqc-395f
- https://github.com/advisories/GHSA-735f-7qx4-jqq5
- https://github.com/apple/swift-nio/pull/2419
- https://github.com/vapor/postgres-nio/commit/2df54bc94607f44584ae6ffa74e3cd754fffafc7
- https://github.com/vapor/postgres-nio/releases/tag/1.14.2
- https://github.com/vapor/postgres-nio/security/advisories/GHSA-9cfh-vx93-84vv
- https://www.postgresql.org/support/security/CVE-2021-23214/
- https://www.postgresql.org/support/security/CVE-2021-23222/
JSON original (NVD)
Mostrar
{
"id": "CVE-2023-31136",
"cveTags": [],
"metrics": {
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2023-31136",
"role": "CISA Coordinator",
"options": [
{
"exploitation": "none"
},
{
"automatable": "no"
},
{
"technicalImpact": "partial"
}
],
"version": "2.0.3",
"timestamp": "2025-01-28T17:04:53.449827Z"
}
}
],
"cvssMetricV31": [
{
"type": "Secondary",
"source": "security-advisories@github.com",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 3.7,
"attackVector": "NETWORK",
"baseSeverity": "LOW",
"vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N",
"integrityImpact": "NONE",
"userInteraction": "NONE",
"attackComplexity": "HIGH",
"availabilityImpact": "NONE",
"privilegesRequired": "NONE",
"confidentialityImpact": "LOW"
},
"impactScore": 1.4,
"exploitabilityScore": 2.2
},
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 5.9,
"attackVector": "NETWORK",
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N",
"integrityImpact": "NONE",
"userInteraction": "NONE",
"attackComplexity": "HIGH",
"availabilityImpact": "NONE",
"privilegesRequired": "NONE",
"confidentialityImpact": "HIGH"
},
"impactScore": 3.6,
"exploitabilityScore": 2.2
}
]
},
"affected": [
{
"source": "security-advisories@github.com",
"affectedData": [
{
"vendor": "vapor",
"product": "postgres-nio",
"versions": [
{
"status": "affected",
"version": "< 1.14.2"
}
]
}
]
}
],
"published": "2023-05-09T14:15:13.520",
"references": [
{
"url": "https://github.com/advisories/GHSA-467w-rrqc-395f",
"tags": [
"Not Applicable"
],
"source": "security-advisories@github.com"
},
{
"url": "https://github.com/advisories/GHSA-735f-7qx4-jqq5",
"tags": [
"Not Applicable"
],
"source": "security-advisories@github.com"
},
{
"url": "https://github.com/apple/swift-nio/pull/2419",
"tags": [
"Patch"
],
"source": "security-advisories@github.com"
},
{
"url": "https://github.com/vapor/postgres-nio/commit/2df54bc94607f44584ae6ffa74e3cd754fffafc7",
"tags": [
"Patch"
],
"source": "security-advisories@github.com"
},
{
"url": "https://github.com/vapor/postgres-nio/releases/tag/1.14.2",
"tags": [
"Release Notes"
],
"source": "security-advisories@github.com"
},
{
"url": "https://github.com/vapor/postgres-nio/security/advisories/GHSA-9cfh-vx93-84vv",
"tags": [
"Vendor Advisory"
],
"source": "security-advisories@github.com"
},
{
"url": "https://www.postgresql.org/support/security/CVE-2021-23214/",
"tags": [
"Not Applicable"
],
"source": "security-advisories@github.com"
},
{
"url": "https://www.postgresql.org/support/security/CVE-2021-23222/",
"tags": [
"Not Applicable"
],
"source": "security-advisories@github.com"
},
{
"url": "https://github.com/advisories/GHSA-467w-rrqc-395f",
"tags": [
"Not Applicable"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://github.com/advisories/GHSA-735f-7qx4-jqq5",
"tags": [
"Not Applicable"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://github.com/apple/swift-nio/pull/2419",
"tags": [
"Patch"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://github.com/vapor/postgres-nio/commit/2df54bc94607f44584ae6ffa74e3cd754fffafc7",
"tags": [
"Patch"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://github.com/vapor/postgres-nio/releases/tag/1.14.2",
"tags": [
"Release Notes"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://github.com/vapor/postgres-nio/security/advisories/GHSA-9cfh-vx93-84vv",
"tags": [
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://www.postgresql.org/support/security/CVE-2021-23214/",
"tags": [
"Not Applicable"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://www.postgresql.org/support/security/CVE-2021-23222/",
"tags": [
"Not Applicable"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Secondary",
"source": "security-advisories@github.com",
"description": [
{
"lang": "en",
"value": "CWE-522"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "PostgresNIO is a Swift client for PostgreSQL. Any user of PostgresNIO prior to version 1.14.2 connecting to servers with TLS enabled is vulnerable to a man-in-the-middle attacker injecting false responses to the client's first few queries, despite the use of TLS certificate verification and encryption. The vulnerability is addressed in PostgresNIO versions starting from 1.14.2. There are no known workarounds for unpatched users."
}
],
"lastModified": "2026-06-17T05:56:21.343",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:vapor:postgresnio:*:*:*:*:*:postgresql:*:*",
"vulnerable": true,
"matchCriteriaId": "F30C6121-3F39-47E8-8EDF-DB10D6A63BDB",
"versionEndExcluding": "1.14.2"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "security-advisories@github.com"
}