Количество 33
Количество 33
BDU:2025-09827
Уязвимость компонента core server системы управления базами данных PostgreSQL, позволяющая нарушителю обойти ограничения безопасности ACL и получить несанкционированный доступ к защищаемой информации
ROS-20250923-14
Множественные уязвимости postgresql-1c
ROS-20250923-13
Множественные уязвимости postgresql17-1c
ROS-20250923-12
Множественные уязвимости postgresql15-1c
ROS-20250923-11
Множественные уязвимости postgresql14
ROS-20250923-10
Множественные уязвимости postgresql17
ROS-20250923-09
Множественные уязвимости postgresql15
ROS-20250923-08
Множественные уязвимости postgresql16
ROS-20250923-07
Множественные уязвимости postgresql13
CVE-2025-8713
PostgreSQL optimizer statistics allow a user to read sampled data within a view that the user cannot access. Separately, statistics allow a user to read sampled data that a row security policy intended to hide. PostgreSQL maintains statistics for tables by sampling data available in columns; this data is consulted during the query planning process. Prior to this release, a user could craft a leaky operator that bypassed view access control lists (ACLs) and bypassed row security policies in partitioning or table inheritance hierarchies. Reachable statistics data notably included histograms and most-common-values lists. CVE-2017-7484 and CVE-2019-10130 intended to close this class of vulnerability, but this gap remained. Versions before PostgreSQL 17.6, 16.10, 15.14, 14.19, and 13.22 are affected.
CVE-2025-8713
PostgreSQL optimizer statistics allow a user to read sampled data within a view that the user cannot access. Separately, statistics allow a user to read sampled data that a row security policy intended to hide. PostgreSQL maintains statistics for tables by sampling data available in columns; this data is consulted during the query planning process. Prior to this release, a user could craft a leaky operator that bypassed view access control lists (ACLs) and bypassed row security policies in partitioning or table inheritance hierarchies. Reachable statistics data notably included histograms and most-common-values lists. CVE-2017-7484 and CVE-2019-10130 intended to close this class of vulnerability, but this gap remained. Versions before PostgreSQL 17.6, 16.10, 15.14, 14.19, and 13.22 are affected.
CVE-2025-8713
PostgreSQL optimizer statistics allow a user to read sampled data within a view that the user cannot access. Separately, statistics allow a user to read sampled data that a row security policy intended to hide. PostgreSQL maintains statistics for tables by sampling data available in columns; this data is consulted during the query planning process. Prior to this release, a user could craft a leaky operator that bypassed view access control lists (ACLs) and bypassed row security policies in partitioning or table inheritance hierarchies. Reachable statistics data notably included histograms and most-common-values lists. CVE-2017-7484 and CVE-2019-10130 intended to close this class of vulnerability, but this gap remained. Versions before PostgreSQL 17.6, 16.10, 15.14, 14.19, and 13.22 are affected.
CVE-2025-8713
PostgreSQL optimizer statistics can expose sampled data within a view, partition, or child table
CVE-2025-8713
PostgreSQL optimizer statistics allow a user to read sampled data with ...
GHSA-cqj3-wjpm-fjvp
PostgreSQL optimizer statistics allow a user to read sampled data within a view that the user cannot access. Separately, statistics allow a user to read sampled data that a row security policy intended to hide. PostgreSQL maintains statistics for tables by sampling data available in columns; this data is consulted during the query planning process. Prior to this release, a user could craft a leaky operator that bypassed view access control lists (ACLs) and bypassed row security policies in partitioning or table inheritance hierarchies. Reachable statistics data notably included histograms and most-common-values lists. CVE-2017-7484 and CVE-2019-10130 intended to close this class of vulnerability, but this gap remained. Versions before PostgreSQL 17.6, 16.10, 15.14, 14.19, and 13.22 are affected.
SUSE-SU-2025:03031-1
Security update for postgresql14
SUSE-SU-2025:03030-1
Security update for postgresql15
SUSE-SU-2025:03020-1
Security update for postgresql14
SUSE-SU-2025:03019-2
Security update for postgresql14
SUSE-SU-2025:03019-1
Security update for postgresql14
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
BDU:2025-09827 Уязвимость компонента core server системы управления базами данных PostgreSQL, позволяющая нарушителю обойти ограничения безопасности ACL и получить несанкционированный доступ к защищаемой информации | CVSS3: 3.1 | 0% Низкий | 3 месяца назад | |
ROS-20250923-14 Множественные уязвимости postgresql-1c | CVSS3: 8.8 | около 1 месяца назад | ||
ROS-20250923-13 Множественные уязвимости postgresql17-1c | CVSS3: 8.8 | около 1 месяца назад | ||
ROS-20250923-12 Множественные уязвимости postgresql15-1c | CVSS3: 8.8 | около 1 месяца назад | ||
ROS-20250923-11 Множественные уязвимости postgresql14 | CVSS3: 8.8 | около 1 месяца назад | ||
ROS-20250923-10 Множественные уязвимости postgresql17 | CVSS3: 8.8 | около 1 месяца назад | ||
ROS-20250923-09 Множественные уязвимости postgresql15 | CVSS3: 8.8 | около 1 месяца назад | ||
ROS-20250923-08 Множественные уязвимости postgresql16 | CVSS3: 8.8 | около 1 месяца назад | ||
ROS-20250923-07 Множественные уязвимости postgresql13 | CVSS3: 8.8 | около 1 месяца назад | ||
CVE-2025-8713 PostgreSQL optimizer statistics allow a user to read sampled data within a view that the user cannot access. Separately, statistics allow a user to read sampled data that a row security policy intended to hide. PostgreSQL maintains statistics for tables by sampling data available in columns; this data is consulted during the query planning process. Prior to this release, a user could craft a leaky operator that bypassed view access control lists (ACLs) and bypassed row security policies in partitioning or table inheritance hierarchies. Reachable statistics data notably included histograms and most-common-values lists. CVE-2017-7484 and CVE-2019-10130 intended to close this class of vulnerability, but this gap remained. Versions before PostgreSQL 17.6, 16.10, 15.14, 14.19, and 13.22 are affected. | CVSS3: 3.1 | 0% Низкий | 3 месяца назад | |
CVE-2025-8713 PostgreSQL optimizer statistics allow a user to read sampled data within a view that the user cannot access. Separately, statistics allow a user to read sampled data that a row security policy intended to hide. PostgreSQL maintains statistics for tables by sampling data available in columns; this data is consulted during the query planning process. Prior to this release, a user could craft a leaky operator that bypassed view access control lists (ACLs) and bypassed row security policies in partitioning or table inheritance hierarchies. Reachable statistics data notably included histograms and most-common-values lists. CVE-2017-7484 and CVE-2019-10130 intended to close this class of vulnerability, but this gap remained. Versions before PostgreSQL 17.6, 16.10, 15.14, 14.19, and 13.22 are affected. | CVSS3: 3.1 | 0% Низкий | 3 месяца назад | |
CVE-2025-8713 PostgreSQL optimizer statistics allow a user to read sampled data within a view that the user cannot access. Separately, statistics allow a user to read sampled data that a row security policy intended to hide. PostgreSQL maintains statistics for tables by sampling data available in columns; this data is consulted during the query planning process. Prior to this release, a user could craft a leaky operator that bypassed view access control lists (ACLs) and bypassed row security policies in partitioning or table inheritance hierarchies. Reachable statistics data notably included histograms and most-common-values lists. CVE-2017-7484 and CVE-2019-10130 intended to close this class of vulnerability, but this gap remained. Versions before PostgreSQL 17.6, 16.10, 15.14, 14.19, and 13.22 are affected. | CVSS3: 3.1 | 0% Низкий | 3 месяца назад | |
CVE-2025-8713 PostgreSQL optimizer statistics can expose sampled data within a view, partition, or child table | CVSS3: 3.1 | 0% Низкий | 2 месяца назад | |
CVE-2025-8713 PostgreSQL optimizer statistics allow a user to read sampled data with ... | CVSS3: 3.1 | 0% Низкий | 3 месяца назад | |
GHSA-cqj3-wjpm-fjvp PostgreSQL optimizer statistics allow a user to read sampled data within a view that the user cannot access. Separately, statistics allow a user to read sampled data that a row security policy intended to hide. PostgreSQL maintains statistics for tables by sampling data available in columns; this data is consulted during the query planning process. Prior to this release, a user could craft a leaky operator that bypassed view access control lists (ACLs) and bypassed row security policies in partitioning or table inheritance hierarchies. Reachable statistics data notably included histograms and most-common-values lists. CVE-2017-7484 and CVE-2019-10130 intended to close this class of vulnerability, but this gap remained. Versions before PostgreSQL 17.6, 16.10, 15.14, 14.19, and 13.22 are affected. | CVSS3: 3.1 | 0% Низкий | 3 месяца назад | |
SUSE-SU-2025:03031-1 Security update for postgresql14 | 2 месяца назад | |||
SUSE-SU-2025:03030-1 Security update for postgresql15 | 2 месяца назад | |||
SUSE-SU-2025:03020-1 Security update for postgresql14 | 2 месяца назад | |||
SUSE-SU-2025:03019-2 Security update for postgresql14 | 22 дня назад | |||
SUSE-SU-2025:03019-1 Security update for postgresql14 | 2 месяца назад |
Уязвимостей на страницу