Логотип exploitDog
product: "postgresql"
Консоль
Логотип exploitDog

exploitDog

product: "postgresql"
PostgreSQL

PostgreSQLсвободная объектно-реляционная система управления базами данных.

Релизный цикл, информация об уязвимостях

Продукт: PostgreSQL
Вендор: PostgreSQL

График релизов

131415161718202020212022202320242025202620272028202920302031

Недавние уязвимости PostgreSQL

Количество 974

suse-cvrf логотип

SUSE-SU-2023:3348-1

около 2 лет назад

Security update for postgresql15

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2023:3346-1

около 2 лет назад

Security update for postgresql12

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2023:3345-1

около 2 лет назад

Security update for postgresql15

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2023:3344-1

около 2 лет назад

Security update for postgresql15

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2023:3343-1

около 2 лет назад

Security update for postgresql15

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2023:3341-1

около 2 лет назад

Security update for postgresql12

EPSS: Низкий
github логотип

GHSA-chgx-7cw3-hr55

около 2 лет назад

A vulnerability was found in PostgreSQL with the use of the MERGE command, which fails to test new rows against row security policies defined for UPDATE and SELECT. If UPDATE and SELECT policies forbid some rows that INSERT policies do not forbid, a user could store such rows.

CVSS3: 3.1
EPSS: Низкий
github логотип

GHSA-jx3x-j983-74m3

около 2 лет назад

IN THE EXTENSION SCRIPT, a SQL Injection vulnerability was found in PostgreSQL if it uses @extowner@, @extschema@, or @extschema:...@ inside a quoting construct (dollar quoting, '', or ""). If an administrator has installed files of a vulnerable, trusted, non-bundled extension, an attacker with database-level CREATE privilege can execute arbitrary code as the bootstrap superuser.

CVSS3: 7.5
EPSS: Низкий
nvd логотип

CVE-2023-39418

около 2 лет назад

A vulnerability was found in PostgreSQL with the use of the MERGE command, which fails to test new rows against row security policies defined for UPDATE and SELECT. If UPDATE and SELECT policies forbid some rows that INSERT policies do not forbid, a user could store such rows.

CVSS3: 3.1
EPSS: Низкий
debian логотип

CVE-2023-39418

около 2 лет назад

A vulnerability was found in PostgreSQL with the use of the MERGE comm ...

CVSS3: 3.1
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
suse-cvrf логотип
SUSE-SU-2023:3348-1

Security update for postgresql15

1%
Низкий
около 2 лет назад
suse-cvrf логотип
SUSE-SU-2023:3346-1

Security update for postgresql12

1%
Низкий
около 2 лет назад
suse-cvrf логотип
SUSE-SU-2023:3345-1

Security update for postgresql15

1%
Низкий
около 2 лет назад
suse-cvrf логотип
SUSE-SU-2023:3344-1

Security update for postgresql15

1%
Низкий
около 2 лет назад
suse-cvrf логотип
SUSE-SU-2023:3343-1

Security update for postgresql15

1%
Низкий
около 2 лет назад
suse-cvrf логотип
SUSE-SU-2023:3341-1

Security update for postgresql12

1%
Низкий
около 2 лет назад
github логотип
GHSA-chgx-7cw3-hr55

A vulnerability was found in PostgreSQL with the use of the MERGE command, which fails to test new rows against row security policies defined for UPDATE and SELECT. If UPDATE and SELECT policies forbid some rows that INSERT policies do not forbid, a user could store such rows.

CVSS3: 3.1
0%
Низкий
около 2 лет назад
github логотип
GHSA-jx3x-j983-74m3

IN THE EXTENSION SCRIPT, a SQL Injection vulnerability was found in PostgreSQL if it uses @extowner@, @extschema@, or @extschema:...@ inside a quoting construct (dollar quoting, '', or ""). If an administrator has installed files of a vulnerable, trusted, non-bundled extension, an attacker with database-level CREATE privilege can execute arbitrary code as the bootstrap superuser.

CVSS3: 7.5
1%
Низкий
около 2 лет назад
nvd логотип
CVE-2023-39418

A vulnerability was found in PostgreSQL with the use of the MERGE command, which fails to test new rows against row security policies defined for UPDATE and SELECT. If UPDATE and SELECT policies forbid some rows that INSERT policies do not forbid, a user could store such rows.

CVSS3: 3.1
0%
Низкий
около 2 лет назад
debian логотип
CVE-2023-39418

A vulnerability was found in PostgreSQL with the use of the MERGE comm ...

CVSS3: 3.1
0%
Низкий
около 2 лет назад

Уязвимостей на страницу


Поделиться