Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-rf5r-cr88-cr97

Опубликовано: 15 фев. 2022
Источник: github
Github: Не прошло ревью
CVSS3: 4.3

Описание

Generation of Error Message Containing Sensitive Information in postgresql

An information leak was discovered in postgresql in versions before 13.2, before 12.6 and before 11.11. A user having UPDATE permission but not SELECT permission to a particular column could craft queries which, under some circumstances, might disclose values from that column in error messages. An attacker could use this flaw to obtain information stored in a column they are allowed to write but not read.

EPSS

Процентиль: 27%
0.00091
Низкий

4.3 Medium

CVSS3

Дефекты

CWE-209

Связанные уязвимости

CVSS3: 4.3
ubuntu
около 4 лет назад

An information leak was discovered in postgresql in versions before 13.2, before 12.6 and before 11.11. A user having UPDATE permission but not SELECT permission to a particular column could craft queries which, under some circumstances, might disclose values from that column in error messages. An attacker could use this flaw to obtain information stored in a column they are allowed to write but not read.

CVSS3: 3.1
redhat
больше 4 лет назад

An information leak was discovered in postgresql in versions before 13.2, before 12.6 and before 11.11. A user having UPDATE permission but not SELECT permission to a particular column could craft queries which, under some circumstances, might disclose values from that column in error messages. An attacker could use this flaw to obtain information stored in a column they are allowed to write but not read.

CVSS3: 4.3
nvd
около 4 лет назад

An information leak was discovered in postgresql in versions before 13.2, before 12.6 and before 11.11. A user having UPDATE permission but not SELECT permission to a particular column could craft queries which, under some circumstances, might disclose values from that column in error messages. An attacker could use this flaw to obtain information stored in a column they are allowed to write but not read.

CVSS3: 4.3
debian
около 4 лет назад

An information leak was discovered in postgresql in versions before 13 ...

suse-cvrf
больше 4 лет назад

Security update for postgresql12

EPSS

Процентиль: 27%
0.00091
Низкий

4.3 Medium

CVSS3

Дефекты

CWE-209