Количество 33
Количество 33
BDU:2025-09827
Уязвимость компонента core server системы управления базами данных PostgreSQL, позволяющая нарушителю обойти ограничения безопасности ACL и получить несанкционированный доступ к защищаемой информации
ROS-20250923-14
Множественные уязвимости postgresql-1c
ROS-20250923-13
Множественные уязвимости postgresql17-1c
ROS-20250923-12
Множественные уязвимости postgresql15-1c
ROS-20250923-11
Множественные уязвимости postgresql14
ROS-20250923-10
Множественные уязвимости postgresql17
ROS-20250923-09
Множественные уязвимости postgresql15
ROS-20250923-08
Множественные уязвимости postgresql16
ROS-20250923-07
Множественные уязвимости postgresql13
CVE-2025-8713
PostgreSQL optimizer statistics allow a user to read sampled data within a view that the user cannot access. Separately, statistics allow a user to read sampled data that a row security policy intended to hide. PostgreSQL maintains statistics for tables by sampling data available in columns; this data is consulted during the query planning process. Prior to this release, a user could craft a leaky operator that bypassed view access control lists (ACLs) and bypassed row security policies in partitioning or table inheritance hierarchies. Reachable statistics data notably included histograms and most-common-values lists. CVE-2017-7484 and CVE-2019-10130 intended to close this class of vulnerability, but this gap remained. Versions before PostgreSQL 17.6, 16.10, 15.14, 14.19, and 13.22 are affected.
CVE-2025-8713
PostgreSQL optimizer statistics allow a user to read sampled data within a view that the user cannot access. Separately, statistics allow a user to read sampled data that a row security policy intended to hide. PostgreSQL maintains statistics for tables by sampling data available in columns; this data is consulted during the query planning process. Prior to this release, a user could craft a leaky operator that bypassed view access control lists (ACLs) and bypassed row security policies in partitioning or table inheritance hierarchies. Reachable statistics data notably included histograms and most-common-values lists. CVE-2017-7484 and CVE-2019-10130 intended to close this class of vulnerability, but this gap remained. Versions before PostgreSQL 17.6, 16.10, 15.14, 14.19, and 13.22 are affected.
CVE-2025-8713
PostgreSQL optimizer statistics allow a user to read sampled data within a view that the user cannot access. Separately, statistics allow a user to read sampled data that a row security policy intended to hide. PostgreSQL maintains statistics for tables by sampling data available in columns; this data is consulted during the query planning process. Prior to this release, a user could craft a leaky operator that bypassed view access control lists (ACLs) and bypassed row security policies in partitioning or table inheritance hierarchies. Reachable statistics data notably included histograms and most-common-values lists. CVE-2017-7484 and CVE-2019-10130 intended to close this class of vulnerability, but this gap remained. Versions before PostgreSQL 17.6, 16.10, 15.14, 14.19, and 13.22 are affected.
CVE-2025-8713
PostgreSQL optimizer statistics can expose sampled data within a view, partition, or child table
CVE-2025-8713
PostgreSQL optimizer statistics allow a user to read sampled data with ...
GHSA-cqj3-wjpm-fjvp
PostgreSQL optimizer statistics allow a user to read sampled data within a view that the user cannot access. Separately, statistics allow a user to read sampled data that a row security policy intended to hide. PostgreSQL maintains statistics for tables by sampling data available in columns; this data is consulted during the query planning process. Prior to this release, a user could craft a leaky operator that bypassed view access control lists (ACLs) and bypassed row security policies in partitioning or table inheritance hierarchies. Reachable statistics data notably included histograms and most-common-values lists. CVE-2017-7484 and CVE-2019-10130 intended to close this class of vulnerability, but this gap remained. Versions before PostgreSQL 17.6, 16.10, 15.14, 14.19, and 13.22 are affected.
SUSE-SU-2025:03031-1
Security update for postgresql14
SUSE-SU-2025:03030-1
Security update for postgresql15
SUSE-SU-2025:03020-1
Security update for postgresql14
SUSE-SU-2025:03019-2
Security update for postgresql14
SUSE-SU-2025:03019-1
Security update for postgresql14
Уязвимостей на страницу
Уязвимость  | CVSS  | EPSS  | Опубликовано  | |
|---|---|---|---|---|
BDU:2025-09827 Уязвимость компонента core server системы управления базами данных PostgreSQL, позволяющая нарушителю обойти ограничения безопасности ACL и получить несанкционированный доступ к защищаемой информации  | CVSS3: 3.1  | 0% Низкий | 3 месяца назад | |
ROS-20250923-14 Множественные уязвимости postgresql-1c  | CVSS3: 8.8  | около 1 месяца назад | ||
ROS-20250923-13 Множественные уязвимости postgresql17-1c  | CVSS3: 8.8  | около 1 месяца назад | ||
ROS-20250923-12 Множественные уязвимости postgresql15-1c  | CVSS3: 8.8  | около 1 месяца назад | ||
ROS-20250923-11 Множественные уязвимости postgresql14  | CVSS3: 8.8  | около 1 месяца назад | ||
ROS-20250923-10 Множественные уязвимости postgresql17  | CVSS3: 8.8  | около 1 месяца назад | ||
ROS-20250923-09 Множественные уязвимости postgresql15  | CVSS3: 8.8  | около 1 месяца назад | ||
ROS-20250923-08 Множественные уязвимости postgresql16  | CVSS3: 8.8  | около 1 месяца назад | ||
ROS-20250923-07 Множественные уязвимости postgresql13  | CVSS3: 8.8  | около 1 месяца назад | ||
CVE-2025-8713 PostgreSQL optimizer statistics allow a user to read sampled data within a view that the user cannot access. Separately, statistics allow a user to read sampled data that a row security policy intended to hide. PostgreSQL maintains statistics for tables by sampling data available in columns; this data is consulted during the query planning process. Prior to this release, a user could craft a leaky operator that bypassed view access control lists (ACLs) and bypassed row security policies in partitioning or table inheritance hierarchies. Reachable statistics data notably included histograms and most-common-values lists. CVE-2017-7484 and CVE-2019-10130 intended to close this class of vulnerability, but this gap remained. Versions before PostgreSQL 17.6, 16.10, 15.14, 14.19, and 13.22 are affected.  | CVSS3: 3.1  | 0% Низкий | 3 месяца назад | |
CVE-2025-8713 PostgreSQL optimizer statistics allow a user to read sampled data within a view that the user cannot access. Separately, statistics allow a user to read sampled data that a row security policy intended to hide. PostgreSQL maintains statistics for tables by sampling data available in columns; this data is consulted during the query planning process. Prior to this release, a user could craft a leaky operator that bypassed view access control lists (ACLs) and bypassed row security policies in partitioning or table inheritance hierarchies. Reachable statistics data notably included histograms and most-common-values lists. CVE-2017-7484 and CVE-2019-10130 intended to close this class of vulnerability, but this gap remained. Versions before PostgreSQL 17.6, 16.10, 15.14, 14.19, and 13.22 are affected.  | CVSS3: 3.1  | 0% Низкий | 3 месяца назад | |
CVE-2025-8713 PostgreSQL optimizer statistics allow a user to read sampled data within a view that the user cannot access. Separately, statistics allow a user to read sampled data that a row security policy intended to hide. PostgreSQL maintains statistics for tables by sampling data available in columns; this data is consulted during the query planning process. Prior to this release, a user could craft a leaky operator that bypassed view access control lists (ACLs) and bypassed row security policies in partitioning or table inheritance hierarchies. Reachable statistics data notably included histograms and most-common-values lists. CVE-2017-7484 and CVE-2019-10130 intended to close this class of vulnerability, but this gap remained. Versions before PostgreSQL 17.6, 16.10, 15.14, 14.19, and 13.22 are affected.  | CVSS3: 3.1  | 0% Низкий | 3 месяца назад | |
CVE-2025-8713 PostgreSQL optimizer statistics can expose sampled data within a view, partition, or child table  | CVSS3: 3.1  | 0% Низкий | 2 месяца назад | |
CVE-2025-8713 PostgreSQL optimizer statistics allow a user to read sampled data with ...  | CVSS3: 3.1  | 0% Низкий | 3 месяца назад | |
GHSA-cqj3-wjpm-fjvp PostgreSQL optimizer statistics allow a user to read sampled data within a view that the user cannot access. Separately, statistics allow a user to read sampled data that a row security policy intended to hide. PostgreSQL maintains statistics for tables by sampling data available in columns; this data is consulted during the query planning process. Prior to this release, a user could craft a leaky operator that bypassed view access control lists (ACLs) and bypassed row security policies in partitioning or table inheritance hierarchies. Reachable statistics data notably included histograms and most-common-values lists. CVE-2017-7484 and CVE-2019-10130 intended to close this class of vulnerability, but this gap remained. Versions before PostgreSQL 17.6, 16.10, 15.14, 14.19, and 13.22 are affected.  | CVSS3: 3.1  | 0% Низкий | 3 месяца назад | |
SUSE-SU-2025:03031-1 Security update for postgresql14  | 2 месяца назад | |||
SUSE-SU-2025:03030-1 Security update for postgresql15  | 2 месяца назад | |||
SUSE-SU-2025:03020-1 Security update for postgresql14  | 2 месяца назад | |||
SUSE-SU-2025:03019-2 Security update for postgresql14  | 22 дня назад | |||
SUSE-SU-2025:03019-1 Security update for postgresql14  | 2 месяца назад | 
Уязвимостей на страницу