Описание
Row security policies disregard user ID changes after inlining; PostgreSQL could permit incorrect policies to be applied in certain cases where role-specific policies are used and a given query is planned under one role and then executed under other roles. This scenario can happen under security definer functions or when a common user and query is planned initially and then re-used across multiple SET ROLEs. Applying an incorrect policy may permit a user to complete otherwise-forbidden reads and modifications. This affects only databases that have used CREATE POLICY to define a row security policy.
| Релиз | Статус | Примечание | 
|---|---|---|
| bionic | DNE  | |
| devel | DNE  | |
| esm-infra/focal | DNE  | |
| focal | DNE  | |
| jammy | DNE  | |
| kinetic | DNE  | |
| lunar | DNE  | |
| mantic | DNE  | |
| noble | DNE  | |
| oracular | DNE  | 
Показывать по
| Релиз | Статус | Примечание | 
|---|---|---|
| bionic | released  | 10.23-0ubuntu0.18.04.2 | 
| devel | DNE  | |
| esm-infra/bionic | released  | 10.23-0ubuntu0.18.04.2 | 
| esm-infra/focal | DNE  | |
| focal | DNE  | |
| jammy | DNE  | |
| kinetic | DNE  | |
| lunar | DNE  | |
| mantic | DNE  | |
| noble | DNE  | 
Показывать по
| Релиз | Статус | Примечание | 
|---|---|---|
| bionic | DNE  | |
| devel | DNE  | |
| esm-infra/focal | released  | 12.15-0ubuntu0.20.04.1 | 
| focal | released  | 12.15-0ubuntu0.20.04.1 | 
| jammy | DNE  | |
| kinetic | DNE  | |
| lunar | DNE  | |
| mantic | DNE  | |
| noble | DNE  | |
| oracular | DNE  | 
Показывать по
| Релиз | Статус | Примечание | 
|---|---|---|
| bionic | DNE  | |
| devel | DNE  | |
| esm-infra/focal | DNE  | |
| focal | DNE  | |
| jammy | released  | 14.8-0ubuntu0.22.04.1 | 
| kinetic | released  | 14.8-0ubuntu0.22.10.1 | 
| lunar | DNE  | |
| mantic | DNE  | |
| noble | DNE  | |
| oracular | DNE  | 
Показывать по
| Релиз | Статус | Примечание | 
|---|---|---|
| bionic | DNE  | |
| devel | DNE  | |
| esm-infra/focal | DNE  | |
| focal | DNE  | |
| jammy | DNE  | |
| kinetic | DNE  | |
| lunar | released  | 15.3-0ubuntu0.23.04.1 | 
| mantic | not-affected  | 15.3-1 | 
| noble | DNE  | |
| oracular | DNE  | 
Показывать по
| Релиз | Статус | Примечание | 
|---|---|---|
| bionic | DNE  | |
| devel | DNE  | |
| esm-infra/focal | DNE  | |
| focal | DNE  | |
| jammy | DNE  | |
| kinetic | DNE  | |
| lunar | DNE  | |
| mantic | DNE  | |
| noble | DNE  | |
| oracular | DNE  | 
Показывать по
| Релиз | Статус | Примечание | 
|---|---|---|
| bionic | DNE  | |
| devel | DNE  | |
| esm-infra-legacy/trusty | deferred  | 2019-08-23 | 
| esm-infra/focal | DNE  | |
| focal | DNE  | |
| jammy | DNE  | |
| kinetic | DNE  | |
| lunar | DNE  | |
| mantic | DNE  | |
| noble | DNE  | 
Показывать по
| Релиз | Статус | Примечание | 
|---|---|---|
| bionic | DNE  | |
| devel | DNE  | |
| esm-infra/focal | DNE  | |
| esm-infra/xenial | ignored  | intrusive backport | 
| focal | DNE  | |
| jammy | DNE  | |
| kinetic | DNE  | |
| lunar | DNE  | |
| mantic | DNE  | |
| noble | DNE  | 
Показывать по
EPSS
5.4 Medium
CVSS3
Связанные уязвимости
Row security policies disregard user ID changes after inlining; PostgreSQL could permit incorrect policies to be applied in certain cases where role-specific policies are used and a given query is planned under one role and then executed under other roles. This scenario can happen under security definer functions or when a common user and query is planned initially and then re-used across multiple SET ROLEs. Applying an incorrect policy may permit a user to complete otherwise-forbidden reads and modifications. This affects only databases that have used CREATE POLICY to define a row security policy.
Row security policies disregard user ID changes after inlining; PostgreSQL could permit incorrect policies to be applied in certain cases where role-specific policies are used and a given query is planned under one role and then executed under other roles. This scenario can happen under security definer functions or when a common user and query is planned initially and then re-used across multiple SET ROLEs. Applying an incorrect policy may permit a user to complete otherwise-forbidden reads and modifications. This affects only databases that have used CREATE POLICY to define a row security policy.
Row security policies disregard user ID changes after inlining; Postgr ...
Row security policies disregard user ID changes after inlining; PostgreSQL could permit incorrect policies to be applied in certain cases where role-specific policies are used and a given query is planned under one role and then executed under other roles. This scenario can happen under security definer functions or when a common user and query is planned initially and then re-used across multiple SET ROLEs. Applying an incorrect policy may permit a user to complete otherwise-forbidden reads and modifications. This affects only databases that have used CREATE POLICY to define a row security policy.
EPSS
5.4 Medium
CVSS3