Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-5qv4-w274-5rpv

Опубликовано: 13 авг. 2026
Источник: github
Github: Не прошло ревью
CVSS3: 3.8

Описание

Incorrect ownership assignment in PostgreSQL ALTER TABLE ALTER TYPE command reassigns ownership of dependent statistics objects to the current user. This wrongly allows the table owner to run DROP STATISTICS and ALTER STATISTICS via this improper ownership. It wrongly denies those commands to the prior statistics object owner. DROP TABLE remains able to remove statistics objects, so this exploit achieves nothing in many ownership arrangements. Versions before PostgreSQL 18.5, 17.11, 16.15, 15.19, and 14.24 are affected.

Incorrect ownership assignment in PostgreSQL ALTER TABLE ALTER TYPE command reassigns ownership of dependent statistics objects to the current user. This wrongly allows the table owner to run DROP STATISTICS and ALTER STATISTICS via this improper ownership. It wrongly denies those commands to the prior statistics object owner. DROP TABLE remains able to remove statistics objects, so this exploit achieves nothing in many ownership arrangements. Versions before PostgreSQL 18.5, 17.11, 16.15, 15.19, and 14.24 are affected.

EPSS

Процентиль: 8%
0.00188
Низкий

3.8 Low

CVSS3

Дефекты

CWE-708

Связанные уязвимости

CVSS3: 3.8
ubuntu
20 дней назад

Incorrect ownership assignment in PostgreSQL ALTER TABLE ALTER TYPE command reassigns ownership of dependent statistics objects to the current user. This wrongly allows the table owner to run DROP STATISTICS and ALTER STATISTICS via this improper ownership. It wrongly denies those commands to the prior statistics object owner. DROP TABLE remains able to remove statistics objects, so this exploit achieves nothing in many ownership arrangements. Versions before PostgreSQL 18.5, 17.11, 16.15, 15.19, and 14.24 are affected.

CVSS3: 3.8
nvd
20 дней назад

Incorrect ownership assignment in PostgreSQL ALTER TABLE ALTER TYPE command reassigns ownership of dependent statistics objects to the current user. This wrongly allows the table owner to run DROP STATISTICS and ALTER STATISTICS via this improper ownership. It wrongly denies those commands to the prior statistics object owner. DROP TABLE remains able to remove statistics objects, so this exploit achieves nothing in many ownership arrangements. Versions before PostgreSQL 18.5, 17.11, 16.15, 15.19, and 14.24 are affected.

CVSS3: 3.8
msrc
18 дней назад

PostgreSQL ALTER TABLE ALTER TYPE resets extended statistics ownership

CVSS3: 3.8
debian
20 дней назад

Incorrect ownership assignment in PostgreSQL ALTER TABLE ALTER TYPE co ...

CVSS3: 3.8
fstec
20 дней назад

Уязвимость команды ALTER TABLE ALTER TYPE системы управления базами данных PostgreSQL, позволяющая нарушителю получить несанкционированный доступ на удаление или изменение данных

EPSS

Процентиль: 8%
0.00188
Низкий

3.8 Low

CVSS3

Дефекты

CWE-708