Описание
PostgreSQL before 9.5.x before 9.5.2 does not properly maintain row-security status in cached plans, which might allow attackers to bypass intended access restrictions by leveraging a session that performs queries as more than one role.
Релиз | Статус | Примечание |
---|---|---|
devel | DNE | |
esm-infra-legacy/trusty | DNE | |
precise | not-affected | 9.5 only |
trusty | DNE | |
trusty/esm | DNE | |
upstream | not-affected | 9.5 only |
vivid/stable-phone-overlay | DNE | |
vivid/ubuntu-core | DNE | |
wily | DNE |
Показывать по
Релиз | Статус | Примечание |
---|---|---|
devel | DNE | |
esm-infra-legacy/trusty | DNE | trusty/esm was DNE [trusty was not-affected [9.5 only]] |
precise | not-affected | 9.5 only |
trusty | not-affected | 9.5 only |
trusty/esm | DNE | trusty was not-affected [9.5 only] |
upstream | not-affected | 9.5 only |
vivid/stable-phone-overlay | DNE | |
vivid/ubuntu-core | DNE | |
wily | DNE |
Показывать по
Релиз | Статус | Примечание |
---|---|---|
devel | DNE | |
esm-infra-legacy/trusty | not-affected | 9.5 only |
precise | DNE | |
trusty | not-affected | 9.5 only |
trusty/esm | not-affected | 9.5 only |
upstream | not-affected | 9.5 only |
vivid/stable-phone-overlay | DNE | |
vivid/ubuntu-core | DNE | |
wily | DNE |
Показывать по
Релиз | Статус | Примечание |
---|---|---|
devel | DNE | |
esm-infra-legacy/trusty | DNE | |
precise | DNE | |
trusty | DNE | |
trusty/esm | DNE | |
upstream | not-affected | 9.5 only |
vivid/stable-phone-overlay | DNE | |
vivid/ubuntu-core | DNE | |
wily | not-affected | 9.5 only |
Показывать по
Релиз | Статус | Примечание |
---|---|---|
devel | not-affected | 9.5.2-1 |
esm-infra-legacy/trusty | DNE | |
precise | DNE | |
trusty | DNE | |
trusty/esm | DNE | |
upstream | released | 9.5.2 |
vivid/stable-phone-overlay | DNE | |
vivid/ubuntu-core | DNE | |
wily | DNE |
Показывать по
EPSS
5 Medium
CVSS2
7.5 High
CVSS3
Связанные уязвимости
PostgreSQL before 9.5.x before 9.5.2 does not properly maintain row-security status in cached plans, which might allow attackers to bypass intended access restrictions by leveraging a session that performs queries as more than one role.
PostgreSQL before 9.5.x before 9.5.2 does not properly maintain row-security status in cached plans, which might allow attackers to bypass intended access restrictions by leveraging a session that performs queries as more than one role.
PostgreSQL before 9.5.x before 9.5.2 does not properly maintain row-se ...
PostgreSQL before 9.5.x before 9.5.2 does not properly maintain row-security status in cached plans, which might allow attackers to bypass intended access restrictions by leveraging a session that performs queries as more than one role.
Уязвимость системы управления базами данных PostgreSQL, позволяющая нарушителю обойти существующие ограничения доступа
EPSS
5 Medium
CVSS2
7.5 High
CVSS3