PostgreSQL — свободная объектно-реляционная система управления базами данных.
Релизный цикл, информация об уязвимостях
График релизов
Релизные элементы
| KB | Версия | Билд | Дата доступности |
|---|---|---|---|
| 17.10 | 17.10 | ||
| 17.9 | 17.9 | ||
| 17.8 | 17.8 | ||
| 17.7 | 17.7 | ||
| 17.6 | 17.6 | ||
| 17.5 | 17.5 | ||
| 17.4 | 17.4 | ||
| 17.3 | 17.3 | ||
| 17.2 | 17.2 | ||
| 17.1 | 17.1 |
Показывать по
Количество 1 129
CVE-2021-3677
A flaw was found in postgresql. A purpose-crafted query can read arbitrary bytes of server memory. In the default configuration, any authenticated database user can complete this attack at will. The attack does not require the ability to create objects. If server settings include max_worker_processes=0, the known versions of this attack are infeasible. However, undiscovered variants of the attack may be independent of that setting.
CVE-2021-3677
A flaw was found in postgresql. A purpose-crafted query can read arbit ...
CVE-2021-23222
A man-in-the-middle attacker can inject false responses to the client's first few queries, despite the use of SSL certificate verification and encryption.
CVE-2021-23222
A man-in-the-middle attacker can inject false responses to the client' ...
CVE-2021-23222
A man-in-the-middle attacker can inject false responses to the client's first few queries, despite the use of SSL certificate verification and encryption.
CVE-2021-3677
A flaw was found in postgresql. A purpose-crafted query can read arbitrary bytes of server memory. In the default configuration, any authenticated database user can complete this attack at will. The attack does not require the ability to create objects. If server settings include max_worker_processes=0, the known versions of this attack are infeasible. However, undiscovered variants of the attack may be independent of that setting.
GHSA-xgxp-9x8p-gcw4
SQL Injection
GHSA-vmm8-82m2-pcp5
Use of a Broken or Risky Cryptographic Algorithm in PostgreSQL
GHSA-6v9v-3f4c-cjgx
Untrusted Search Path in PostgreSQL
GHSA-rf5r-cr88-cr97
Generation of Error Message Containing Sensitive Information in postgresql
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано 1 | |
|---|---|---|---|---|
CVE-2021-3677 A flaw was found in postgresql. A purpose-crafted query can read arbitrary bytes of server memory. In the default configuration, any authenticated database user can complete this attack at will. The attack does not require the ability to create objects. If server settings include max_worker_processes=0, the known versions of this attack are infeasible. However, undiscovered variants of the attack may be independent of that setting. | CVSS3: 6.5 | 1% Низкий | больше 4 лет назад | |
CVE-2021-3677 A flaw was found in postgresql. A purpose-crafted query can read arbit ... | CVSS3: 6.5 | 1% Низкий | больше 4 лет назад | |
CVE-2021-23222 A man-in-the-middle attacker can inject false responses to the client's first few queries, despite the use of SSL certificate verification and encryption. | CVSS3: 5.9 | 2% Низкий | больше 4 лет назад | |
CVE-2021-23222 A man-in-the-middle attacker can inject false responses to the client' ... | CVSS3: 5.9 | 2% Низкий | больше 4 лет назад | |
CVE-2021-23222 A man-in-the-middle attacker can inject false responses to the client's first few queries, despite the use of SSL certificate verification and encryption. | CVSS3: 5.9 | 2% Низкий | больше 4 лет назад | |
CVE-2021-3677 A flaw was found in postgresql. A purpose-crafted query can read arbitrary bytes of server memory. In the default configuration, any authenticated database user can complete this attack at will. The attack does not require the ability to create objects. If server settings include max_worker_processes=0, the known versions of this attack are infeasible. However, undiscovered variants of the attack may be independent of that setting. | CVSS3: 6.5 | 1% Низкий | больше 4 лет назад | |
GHSA-xgxp-9x8p-gcw4 SQL Injection | CVSS3: 8.8 | 46% Средний | больше 4 лет назад | |
GHSA-vmm8-82m2-pcp5 Use of a Broken or Risky Cryptographic Algorithm in PostgreSQL | CVSS3: 8.1 | 2% Низкий | больше 4 лет назад | |
GHSA-6v9v-3f4c-cjgx Untrusted Search Path in PostgreSQL | CVSS3: 7.3 | 1% Низкий | больше 4 лет назад | |
GHSA-rf5r-cr88-cr97 Generation of Error Message Containing Sensitive Information in postgresql | CVSS3: 4.3 | 1% Низкий | больше 4 лет назад |
Уязвимостей на страницу