Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2021-20229

Опубликовано: 11 фев. 2021
Источник: redhat
CVSS3: 3.1
EPSS Низкий

Описание

A flaw was found in PostgreSQL in versions before 13.2. This flaw allows a user with SELECT privilege on one column to craft a special query that returns all columns of the table. The highest threat from this vulnerability is to confidentiality.

A flaw was found in PostgreSQL. This flaw allows a user with SELECT privilege on one column to craft a special query that returns all columns of the table. The highest threat from this vulnerability is to confidentiality.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat build of QuarkuspostgresqlNot affected
Red Hat Decision Manager 7postgresqlNot affected
Red Hat Enterprise Linux 6postgresqlOut of support scope
Red Hat Enterprise Linux 7postgresqlFix deferred
Red Hat Enterprise Linux 8libpqNot affected
Red Hat Enterprise Linux 8postgresql:10/postgresqlNot affected
Red Hat Enterprise Linux 8postgresql:12/postgresqlNot affected
Red Hat Enterprise Linux 8postgresql:9.6/postgresqlNot affected
Red Hat Enterprise Linux 9postgresqlNot affected
Red Hat Fuse 7postgresqlNot affected

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-863
https://bugzilla.redhat.com/show_bug.cgi?id=1925296postgresql: single-column SELECT privilege enables reading all columns

EPSS

Процентиль: 25%
0.00086
Низкий

3.1 Low

CVSS3

Связанные уязвимости

CVSS3: 4.3
ubuntu
почти 5 лет назад

A flaw was found in PostgreSQL in versions before 13.2. This flaw allows a user with SELECT privilege on one column to craft a special query that returns all columns of the table. The highest threat from this vulnerability is to confidentiality.

CVSS3: 4.3
nvd
почти 5 лет назад

A flaw was found in PostgreSQL in versions before 13.2. This flaw allows a user with SELECT privilege on one column to craft a special query that returns all columns of the table. The highest threat from this vulnerability is to confidentiality.

CVSS3: 4.3
msrc
почти 5 лет назад

A flaw was found in PostgreSQL in versions before 13.2. This flaw allows a user with SELECT privilege on one column to craft a special query that returns all columns of the table. The highest threat from this vulnerability is to confidentiality.

CVSS3: 4.3
debian
почти 5 лет назад

A flaw was found in PostgreSQL in versions before 13.2. This flaw allo ...

CVSS3: 4.3
github
почти 4 года назад

Incorrect Authorization in PostgreSQL

EPSS

Процентиль: 25%
0.00086
Низкий

3.1 Low

CVSS3