Описание
An authenticated user holding cursor termination privileges on one database may incorrectly be permitted to terminate active cursors on a separate database, disrupting ongoing query operations for other users. The behavior stems from an authorization check that does not correctly scope privileges to the appropriate namespace.
Ссылки
- Vendor AdvisoryIssue TrackingPatch
Уязвимые конфигурации
Одно из
EPSS
4.2 Medium
CVSS3
4.3 Medium
CVSS3
Дефекты
Связанные уязвимости
An authenticated user holding cursor termination privileges on one database may incorrectly be permitted to terminate active cursors on a separate database, disrupting ongoing query operations for other users. The behavior stems from an authorization check that does not correctly scope privileges to the appropriate namespace.
An authenticated user holding cursor termination privileges on one dat ...
An authenticated user holding cursor termination privileges on one database may incorrectly be permitted to terminate active cursors on a separate database, disrupting ongoing query operations for other users. The behavior stems from an authorization check that does not correctly scope privileges to the appropriate namespace.
EPSS
4.2 Medium
CVSS3
4.3 Medium
CVSS3