Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2021-3393

Опубликовано: 01 апр. 2021
Источник: debian
EPSS Низкий

Описание

An information leak was discovered in postgresql in versions before 13.2, before 12.6 and before 11.11. A user having UPDATE permission but not SELECT permission to a particular column could craft queries which, under some circumstances, might disclose values from that column in error messages. An attacker could use this flaw to obtain information stored in a column they are allowed to write but not read.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
postgresql-13fixed13.2-1package
postgresql-11removedpackage
postgresql-11fixed11.11-0+deb10u1busterpackage

Примечания

  • https://www.postgresql.org/about/news/postgresql-132-126-1111-1016-9621-and-9525-released-2165/

EPSS

Процентиль: 27%
0.00091
Низкий

Связанные уязвимости

CVSS3: 4.3
ubuntu
около 4 лет назад

An information leak was discovered in postgresql in versions before 13.2, before 12.6 and before 11.11. A user having UPDATE permission but not SELECT permission to a particular column could craft queries which, under some circumstances, might disclose values from that column in error messages. An attacker could use this flaw to obtain information stored in a column they are allowed to write but not read.

CVSS3: 3.1
redhat
больше 4 лет назад

An information leak was discovered in postgresql in versions before 13.2, before 12.6 and before 11.11. A user having UPDATE permission but not SELECT permission to a particular column could craft queries which, under some circumstances, might disclose values from that column in error messages. An attacker could use this flaw to obtain information stored in a column they are allowed to write but not read.

CVSS3: 4.3
nvd
около 4 лет назад

An information leak was discovered in postgresql in versions before 13.2, before 12.6 and before 11.11. A user having UPDATE permission but not SELECT permission to a particular column could craft queries which, under some circumstances, might disclose values from that column in error messages. An attacker could use this flaw to obtain information stored in a column they are allowed to write but not read.

suse-cvrf
больше 4 лет назад

Security update for postgresql12

suse-cvrf
больше 4 лет назад

Security update for postgresql12

EPSS

Процентиль: 27%
0.00091
Низкий