Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2017-15099

Опубликовано: 09 нояб. 2017
Источник: redhat
CVSS3: 3.1
EPSS Средний

Описание

INSERT ... ON CONFLICT DO UPDATE commands in PostgreSQL 10.x before 10.1, 9.6.x before 9.6.6, and 9.5.x before 9.5.10 disclose table contents that the invoker lacks privilege to read. These exploits affect only tables where the attacker lacks full read access but has both INSERT and UPDATE privileges. Exploits bypass row level security policies and lack of SELECT privilege.

Отчет

This issue affects the versions of rh-postgresql95-postgresql, and rh-postgresql96-postgresql as shipped with Red Hat Software Collections 3. Red Hat Product Security has rated this issue as having Low security impact. A future update may address this issue. For additional information, refer to the Issue Severity Classification: https://access.redhat.com/security/updates/classification/.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 5postgresqlNot affected
Red Hat Enterprise Linux 5postgresql84Not affected
Red Hat Enterprise Linux 6postgresqlNot affected
Red Hat Enterprise Linux 7postgresqlNot affected
Red Hat Satellite 5postgresql92-postgresqlNot affected
Red Hat Software Collectionsrh-postgresql94-postgresqlNot affected
Red Hat Software Collections for Red Hat Enterprise Linux 6rh-postgresql95-postgresqlFixedRHSA-2018:251120.08.2018
Red Hat Software Collections for Red Hat Enterprise Linux 6rh-postgresql96-postgresqlFixedRHSA-2018:256627.08.2018
Red Hat Software Collections for Red Hat Enterprise Linux 6.7 EUSrh-postgresql95-postgresqlFixedRHSA-2018:251120.08.2018
Red Hat Software Collections for Red Hat Enterprise Linux 6.7 EUSrh-postgresql96-postgresqlFixedRHSA-2018:256627.08.2018

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-200
https://bugzilla.redhat.com/show_bug.cgi?id=1508823postgresql: INSERT ... ON CONFLICT DO UPDATE fails to enforce SELECT privileges

EPSS

Процентиль: 97%
0.3401
Средний

3.1 Low

CVSS3

Связанные уязвимости

CVSS3: 6.5
ubuntu
больше 7 лет назад

INSERT ... ON CONFLICT DO UPDATE commands in PostgreSQL 10.x before 10.1, 9.6.x before 9.6.6, and 9.5.x before 9.5.10 disclose table contents that the invoker lacks privilege to read. These exploits affect only tables where the attacker lacks full read access but has both INSERT and UPDATE privileges. Exploits bypass row level security policies and lack of SELECT privilege.

CVSS3: 6.5
nvd
больше 7 лет назад

INSERT ... ON CONFLICT DO UPDATE commands in PostgreSQL 10.x before 10.1, 9.6.x before 9.6.6, and 9.5.x before 9.5.10 disclose table contents that the invoker lacks privilege to read. These exploits affect only tables where the attacker lacks full read access but has both INSERT and UPDATE privileges. Exploits bypass row level security policies and lack of SELECT privilege.

CVSS3: 6.5
debian
больше 7 лет назад

INSERT ... ON CONFLICT DO UPDATE commands in PostgreSQL 10.x before 10 ...

CVSS3: 6.5
github
около 3 лет назад

INSERT ... ON CONFLICT DO UPDATE commands in PostgreSQL 10.x before 10.1, 9.6.x before 9.6.6, and 9.5.x before 9.5.10 disclose table contents that the invoker lacks privilege to read. These exploits affect only tables where the attacker lacks full read access but has both INSERT and UPDATE privileges. Exploits bypass row level security policies and lack of SELECT privilege.

CVSS3: 6.5
fstec
почти 8 лет назад

Уязвимость реализации команды «INSERT ... ON CONFLICT DO UPDATE» системы управления базами данных PostgreSQL, позволяющая нарушителю получить несанкционированный доступ к защищаемой информации

EPSS

Процентиль: 97%
0.3401
Средний

3.1 Low

CVSS3