Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-43rr-wcj9-h45w

Опубликовано: 15 фев. 2022
Источник: github
Github: Не прошло ревью
CVSS3: 4.3

Описание

Incorrect Authorization in PostgreSQL

A flaw was found in PostgreSQL in versions before 13.2, before 12.6, before 11.11, before 10.16, before 9.6.21 and before 9.5.25. This flaw allows a user with SELECT privilege on one column to craft a special query that returns all columns of the table. The highest threat from this vulnerability is to confidentiality.

EPSS

Процентиль: 26%
0.00084
Низкий

4.3 Medium

CVSS3

Дефекты

CWE-863

Связанные уязвимости

CVSS3: 4.3
ubuntu
больше 4 лет назад

A flaw was found in PostgreSQL in versions before 13.2. This flaw allows a user with SELECT privilege on one column to craft a special query that returns all columns of the table. The highest threat from this vulnerability is to confidentiality.

CVSS3: 3.1
redhat
больше 4 лет назад

A flaw was found in PostgreSQL in versions before 13.2. This flaw allows a user with SELECT privilege on one column to craft a special query that returns all columns of the table. The highest threat from this vulnerability is to confidentiality.

CVSS3: 4.3
nvd
больше 4 лет назад

A flaw was found in PostgreSQL in versions before 13.2. This flaw allows a user with SELECT privilege on one column to craft a special query that returns all columns of the table. The highest threat from this vulnerability is to confidentiality.

CVSS3: 4.3
msrc
больше 4 лет назад

Описание отсутствует

CVSS3: 4.3
debian
больше 4 лет назад

A flaw was found in PostgreSQL in versions before 13.2. This flaw allo ...

EPSS

Процентиль: 26%
0.00084
Низкий

4.3 Medium

CVSS3

Дефекты

CWE-863