Описание
PostgreSQL before 9.5.x before 9.5.2 does not properly maintain row-security status in cached plans, which might allow attackers to bypass intended access restrictions by leveraging a session that performs queries as more than one role.
Затронутые пакеты
Платформа | Пакет | Состояние | Рекомендация | Релиз |
---|---|---|---|---|
CloudForms Management Engine 5 | postgresql | Not affected | ||
CloudForms Management Engine 5 | postgresql92-postgresql | Not affected | ||
Red Hat Enterprise Linux 5 | postgresql | Not affected | ||
Red Hat Enterprise Linux 5 | postgresql84 | Not affected | ||
Red Hat Enterprise Linux 6 | postgresql | Not affected | ||
Red Hat Enterprise Linux 7 | postgresql | Not affected | ||
Red Hat Satellite 5.7 | postgresql92-postgresql | Not affected | ||
Red Hat Software Collections | postgresql92-postgresql | Not affected | ||
Red Hat Software Collections | rh-postgresql94-postgresql | Not affected | ||
Red Hat Software Collections | rh-postgresql95-postgresql | Not affected |
Показывать по
Дополнительная информация
Статус:
EPSS
4.6 Medium
CVSS2
Связанные уязвимости
PostgreSQL before 9.5.x before 9.5.2 does not properly maintain row-security status in cached plans, which might allow attackers to bypass intended access restrictions by leveraging a session that performs queries as more than one role.
PostgreSQL before 9.5.x before 9.5.2 does not properly maintain row-security status in cached plans, which might allow attackers to bypass intended access restrictions by leveraging a session that performs queries as more than one role.
PostgreSQL before 9.5.x before 9.5.2 does not properly maintain row-se ...
PostgreSQL before 9.5.x before 9.5.2 does not properly maintain row-security status in cached plans, which might allow attackers to bypass intended access restrictions by leveraging a session that performs queries as more than one role.
Уязвимость системы управления базами данных PostgreSQL, позволяющая нарушителю обойти существующие ограничения доступа
EPSS
4.6 Medium
CVSS2