Логотип exploitDog
bind:"GHSA-9cv8-8vgq-fg45" OR bind:"CVE-2024-10976"
Консоль
Логотип exploitDog

exploitDog

bind:"GHSA-9cv8-8vgq-fg45" OR bind:"CVE-2024-10976"

Количество 35

Количество 35

github логотип

GHSA-9cv8-8vgq-fg45

7 месяцев назад

Incomplete tracking in PostgreSQL of tables with row security allows a reused query to view or change different rows from those intended. CVE-2023-2455 and CVE-2016-2193 fixed most interaction between row security and user ID changes. They missed cases where a subquery, WITH query, security invoker view, or SQL-language function references a table with a row-level security policy. This has the same consequences as the two earlier CVEs. That is to say, it leads to potentially incorrect policies being applied in cases where role-specific policies are used and a given query is planned under one role and then executed under other roles. This scenario can happen under security definer functions or when a common user and query is planned initially and then re-used across multiple SET ROLEs. Applying an incorrect policy may permit a user to complete otherwise-forbidden reads and modifications. This affects only databases that have used CREATE POLICY to define a row security policy. ...

CVSS3: 4.2
EPSS: Низкий
ubuntu логотип

CVE-2024-10976

7 месяцев назад

Incomplete tracking in PostgreSQL of tables with row security allows a reused query to view or change different rows from those intended. CVE-2023-2455 and CVE-2016-2193 fixed most interaction between row security and user ID changes. They missed cases where a subquery, WITH query, security invoker view, or SQL-language function references a table with a row-level security policy. This has the same consequences as the two earlier CVEs. That is to say, it leads to potentially incorrect policies being applied in cases where role-specific policies are used and a given query is planned under one role and then executed under other roles. This scenario can happen under security definer functions or when a common user and query is planned initially and then re-used across multiple SET ROLEs. Applying an incorrect policy may permit a user to complete otherwise-forbidden reads and modifications. This affects only databases that have used CREATE POLICY to define a row security policy. A...

CVSS3: 4.2
EPSS: Низкий
redhat логотип

CVE-2024-10976

7 месяцев назад

Incomplete tracking in PostgreSQL of tables with row security allows a reused query to view or change different rows from those intended. CVE-2023-2455 and CVE-2016-2193 fixed most interaction between row security and user ID changes. They missed cases where a subquery, WITH query, security invoker view, or SQL-language function references a table with a row-level security policy. This has the same consequences as the two earlier CVEs. That is to say, it leads to potentially incorrect policies being applied in cases where role-specific policies are used and a given query is planned under one role and then executed under other roles. This scenario can happen under security definer functions or when a common user and query is planned initially and then re-used across multiple SET ROLEs. Applying an incorrect policy may permit a user to complete otherwise-forbidden reads and modifications. This affects only databases that have used CREATE POLICY to define a row security policy. ...

CVSS3: 4.2
EPSS: Низкий
nvd логотип

CVE-2024-10976

7 месяцев назад

Incomplete tracking in PostgreSQL of tables with row security allows a reused query to view or change different rows from those intended. CVE-2023-2455 and CVE-2016-2193 fixed most interaction between row security and user ID changes. They missed cases where a subquery, WITH query, security invoker view, or SQL-language function references a table with a row-level security policy. This has the same consequences as the two earlier CVEs. That is to say, it leads to potentially incorrect policies being applied in cases where role-specific policies are used and a given query is planned under one role and then executed under other roles. This scenario can happen under security definer functions or when a common user and query is planned initially and then re-used across multiple SET ROLEs. Applying an incorrect policy may permit a user to complete otherwise-forbidden reads and modifications. This affects only databases that have used CREATE POLICY to define a row security policy. An

CVSS3: 4.2
EPSS: Низкий
msrc логотип

CVE-2024-10976

7 месяцев назад

CVSS3: 5.4
EPSS: Низкий
debian логотип

CVE-2024-10976

7 месяцев назад

Incomplete tracking in PostgreSQL of tables with row security allows a ...

CVSS3: 4.2
EPSS: Низкий
fstec логотип

BDU:2024-09684

7 месяцев назад

Уязвимость политики безопасности таблиц с защитой строк CREATE POLICY системы управления базами данных PostgreSQL, позволяющая нарушителю выполнить произвольные команды

CVSS3: 4.2
EPSS: Низкий
oracle-oval логотип

ELSA-2024-10832

7 месяцев назад

ELSA-2024-10832: postgresql:13 security update (IMPORTANT)

EPSS: Низкий
oracle-oval логотип

ELSA-2024-10831

7 месяцев назад

ELSA-2024-10831: postgresql:16 security update (IMPORTANT)

EPSS: Низкий
oracle-oval логотип

ELSA-2024-10830

7 месяцев назад

ELSA-2024-10830: postgresql:15 security update (IMPORTANT)

EPSS: Низкий
oracle-oval логотип

ELSA-2024-10791

6 месяцев назад

ELSA-2024-10791: postgresql security update (IMPORTANT)

EPSS: Низкий
oracle-oval логотип

ELSA-2024-10788

7 месяцев назад

ELSA-2024-10788: postgresql:16 security update (IMPORTANT)

EPSS: Низкий
oracle-oval логотип

ELSA-2024-10787

7 месяцев назад

ELSA-2024-10787: postgresql:15 security update (IMPORTANT)

EPSS: Низкий
oracle-oval логотип

ELSA-2024-10785

7 месяцев назад

ELSA-2024-10785: postgresql:12 security update (IMPORTANT)

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2025:01799-1

17 дней назад

Security update for postgresql, postgresql16, postgresql17

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2024:4176-1

7 месяцев назад

Security update for postgresql14

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2024:4175-1

7 месяцев назад

Security update for postgresql13

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2024:4174-1

7 месяцев назад

Security update for postgresql15

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2024:4173-1

7 месяцев назад

Security update for postgresql, postgresql16, postgresql17

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2024:4118-1

7 месяцев назад

Security update for postgresql14

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-9cv8-8vgq-fg45

Incomplete tracking in PostgreSQL of tables with row security allows a reused query to view or change different rows from those intended. CVE-2023-2455 and CVE-2016-2193 fixed most interaction between row security and user ID changes. They missed cases where a subquery, WITH query, security invoker view, or SQL-language function references a table with a row-level security policy. This has the same consequences as the two earlier CVEs. That is to say, it leads to potentially incorrect policies being applied in cases where role-specific policies are used and a given query is planned under one role and then executed under other roles. This scenario can happen under security definer functions or when a common user and query is planned initially and then re-used across multiple SET ROLEs. Applying an incorrect policy may permit a user to complete otherwise-forbidden reads and modifications. This affects only databases that have used CREATE POLICY to define a row security policy. ...

CVSS3: 4.2
0%
Низкий
7 месяцев назад
ubuntu логотип
CVE-2024-10976

Incomplete tracking in PostgreSQL of tables with row security allows a reused query to view or change different rows from those intended. CVE-2023-2455 and CVE-2016-2193 fixed most interaction between row security and user ID changes. They missed cases where a subquery, WITH query, security invoker view, or SQL-language function references a table with a row-level security policy. This has the same consequences as the two earlier CVEs. That is to say, it leads to potentially incorrect policies being applied in cases where role-specific policies are used and a given query is planned under one role and then executed under other roles. This scenario can happen under security definer functions or when a common user and query is planned initially and then re-used across multiple SET ROLEs. Applying an incorrect policy may permit a user to complete otherwise-forbidden reads and modifications. This affects only databases that have used CREATE POLICY to define a row security policy. A...

CVSS3: 4.2
0%
Низкий
7 месяцев назад
redhat логотип
CVE-2024-10976

Incomplete tracking in PostgreSQL of tables with row security allows a reused query to view or change different rows from those intended. CVE-2023-2455 and CVE-2016-2193 fixed most interaction between row security and user ID changes. They missed cases where a subquery, WITH query, security invoker view, or SQL-language function references a table with a row-level security policy. This has the same consequences as the two earlier CVEs. That is to say, it leads to potentially incorrect policies being applied in cases where role-specific policies are used and a given query is planned under one role and then executed under other roles. This scenario can happen under security definer functions or when a common user and query is planned initially and then re-used across multiple SET ROLEs. Applying an incorrect policy may permit a user to complete otherwise-forbidden reads and modifications. This affects only databases that have used CREATE POLICY to define a row security policy. ...

CVSS3: 4.2
0%
Низкий
7 месяцев назад
nvd логотип
CVE-2024-10976

Incomplete tracking in PostgreSQL of tables with row security allows a reused query to view or change different rows from those intended. CVE-2023-2455 and CVE-2016-2193 fixed most interaction between row security and user ID changes. They missed cases where a subquery, WITH query, security invoker view, or SQL-language function references a table with a row-level security policy. This has the same consequences as the two earlier CVEs. That is to say, it leads to potentially incorrect policies being applied in cases where role-specific policies are used and a given query is planned under one role and then executed under other roles. This scenario can happen under security definer functions or when a common user and query is planned initially and then re-used across multiple SET ROLEs. Applying an incorrect policy may permit a user to complete otherwise-forbidden reads and modifications. This affects only databases that have used CREATE POLICY to define a row security policy. An

CVSS3: 4.2
0%
Низкий
7 месяцев назад
msrc логотип
CVSS3: 5.4
0%
Низкий
7 месяцев назад
debian логотип
CVE-2024-10976

Incomplete tracking in PostgreSQL of tables with row security allows a ...

CVSS3: 4.2
0%
Низкий
7 месяцев назад
fstec логотип
BDU:2024-09684

Уязвимость политики безопасности таблиц с защитой строк CREATE POLICY системы управления базами данных PostgreSQL, позволяющая нарушителю выполнить произвольные команды

CVSS3: 4.2
0%
Низкий
7 месяцев назад
oracle-oval логотип
ELSA-2024-10832

ELSA-2024-10832: postgresql:13 security update (IMPORTANT)

7 месяцев назад
oracle-oval логотип
ELSA-2024-10831

ELSA-2024-10831: postgresql:16 security update (IMPORTANT)

7 месяцев назад
oracle-oval логотип
ELSA-2024-10830

ELSA-2024-10830: postgresql:15 security update (IMPORTANT)

7 месяцев назад
oracle-oval логотип
ELSA-2024-10791

ELSA-2024-10791: postgresql security update (IMPORTANT)

6 месяцев назад
oracle-oval логотип
ELSA-2024-10788

ELSA-2024-10788: postgresql:16 security update (IMPORTANT)

7 месяцев назад
oracle-oval логотип
ELSA-2024-10787

ELSA-2024-10787: postgresql:15 security update (IMPORTANT)

7 месяцев назад
oracle-oval логотип
ELSA-2024-10785

ELSA-2024-10785: postgresql:12 security update (IMPORTANT)

7 месяцев назад
suse-cvrf логотип
SUSE-SU-2025:01799-1

Security update for postgresql, postgresql16, postgresql17

17 дней назад
suse-cvrf логотип
SUSE-SU-2024:4176-1

Security update for postgresql14

7 месяцев назад
suse-cvrf логотип
SUSE-SU-2024:4175-1

Security update for postgresql13

7 месяцев назад
suse-cvrf логотип
SUSE-SU-2024:4174-1

Security update for postgresql15

7 месяцев назад
suse-cvrf логотип
SUSE-SU-2024:4173-1

Security update for postgresql, postgresql16, postgresql17

7 месяцев назад
suse-cvrf логотип
SUSE-SU-2024:4118-1

Security update for postgresql14

7 месяцев назад

Уязвимостей на страницу