Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-2pm8-9426-243p

Опубликовано: 13 авг. 2026
Источник: github
Github: Не прошло ревью
CVSS3: 4.3

Описание

Missing authorization in PostgreSQL DDL commands allows an object creator to achieve denial of service against ALTER and DROP of the type, via creating a dependency on the type. Many DDL operations did check the privilege, but assigning a range subtype and referencing the type from an SQL expression did not. Versions before PostgreSQL 18.5, 17.11, 16.15, 15.19, and 14.24 are affected.

Missing authorization in PostgreSQL DDL commands allows an object creator to achieve denial of service against ALTER and DROP of the type, via creating a dependency on the type. Many DDL operations did check the privilege, but assigning a range subtype and referencing the type from an SQL expression did not. Versions before PostgreSQL 18.5, 17.11, 16.15, 15.19, and 14.24 are affected.

EPSS

Процентиль: 9%
0.00195
Низкий

4.3 Medium

CVSS3

Дефекты

CWE-862

Связанные уязвимости

CVSS3: 4.3
ubuntu
20 дней назад

Missing authorization in PostgreSQL DDL commands allows an object creator to achieve denial of service against ALTER and DROP of the type, via creating a dependency on the type. Many DDL operations did check the privilege, but assigning a range subtype and referencing the type from an SQL expression did not. Versions before PostgreSQL 18.5, 17.11, 16.15, 15.19, and 14.24 are affected.

CVSS3: 4.3
nvd
20 дней назад

Missing authorization in PostgreSQL DDL commands allows an object creator to achieve denial of service against ALTER and DROP of the type, via creating a dependency on the type. Many DDL operations did check the privilege, but assigning a range subtype and referencing the type from an SQL expression did not. Versions before PostgreSQL 18.6, 17.11, 16.15, 15.19, and 14.24 are affected.

CVSS3: 4.3
msrc
9 дней назад

PostgreSQL fails to check type USAGE privilege

CVSS3: 4.3
debian
20 дней назад

Missing authorization in PostgreSQL DDL commands allows an object crea ...

CVSS3: 4.3
fstec
20 дней назад

Уязвимость DDL-команд системы управления базами данных PostgreSQL, позволяющая нарушителю вызвать отказ в обслуживании

EPSS

Процентиль: 9%
0.00195
Низкий

4.3 Medium

CVSS3

Дефекты

CWE-862