Количество 21
Количество 21
GHSA-cqj3-wjpm-fjvp
PostgreSQL optimizer statistics allow a user to read sampled data within a view that the user cannot access. Separately, statistics allow a user to read sampled data that a row security policy intended to hide. PostgreSQL maintains statistics for tables by sampling data available in columns; this data is consulted during the query planning process. Prior to this release, a user could craft a leaky operator that bypassed view access control lists (ACLs) and bypassed row security policies in partitioning or table inheritance hierarchies. Reachable statistics data notably included histograms and most-common-values lists. CVE-2017-7484 and CVE-2019-10130 intended to close this class of vulnerability, but this gap remained. Versions before PostgreSQL 17.6, 16.10, 15.14, 14.19, and 13.22 are affected.

CVE-2025-8713
PostgreSQL optimizer statistics allow a user to read sampled data within a view that the user cannot access. Separately, statistics allow a user to read sampled data that a row security policy intended to hide. PostgreSQL maintains statistics for tables by sampling data available in columns; this data is consulted during the query planning process. Prior to this release, a user could craft a leaky operator that bypassed view access control lists (ACLs) and bypassed row security policies in partitioning or table inheritance hierarchies. Reachable statistics data notably included histograms and most-common-values lists. CVE-2017-7484 and CVE-2019-10130 intended to close this class of vulnerability, but this gap remained. Versions before PostgreSQL 17.6, 16.10, 15.14, 14.19, and 13.22 are affected.

CVE-2025-8713
PostgreSQL optimizer statistics allow a user to read sampled data within a view that the user cannot access. Separately, statistics allow a user to read sampled data that a row security policy intended to hide. PostgreSQL maintains statistics for tables by sampling data available in columns; this data is consulted during the query planning process. Prior to this release, a user could craft a leaky operator that bypassed view access control lists (ACLs) and bypassed row security policies in partitioning or table inheritance hierarchies. Reachable statistics data notably included histograms and most-common-values lists. CVE-2017-7484 and CVE-2019-10130 intended to close this class of vulnerability, but this gap remained. Versions before PostgreSQL 17.6, 16.10, 15.14, 14.19, and 13.22 are affected.

CVE-2025-8713
PostgreSQL optimizer statistics allow a user to read sampled data within a view that the user cannot access. Separately, statistics allow a user to read sampled data that a row security policy intended to hide. PostgreSQL maintains statistics for tables by sampling data available in columns; this data is consulted during the query planning process. Prior to this release, a user could craft a leaky operator that bypassed view access control lists (ACLs) and bypassed row security policies in partitioning or table inheritance hierarchies. Reachable statistics data notably included histograms and most-common-values lists. CVE-2017-7484 and CVE-2019-10130 intended to close this class of vulnerability, but this gap remained. Versions before PostgreSQL 17.6, 16.10, 15.14, 14.19, and 13.22 are affected.
CVE-2025-8713
PostgreSQL optimizer statistics allow a user to read sampled data with ...

BDU:2025-09827
Уязвимость компонента core server системы управления базами данных PostgreSQL, позволяющая нарушителю обойти ограничения безопасности ACL и получить несанкционированный доступ к защищаемой информации

SUSE-SU-2025:03031-1
Security update for postgresql14

SUSE-SU-2025:03030-1
Security update for postgresql15

SUSE-SU-2025:03020-1
Security update for postgresql14

SUSE-SU-2025:03019-1
Security update for postgresql14

SUSE-SU-2025:03018-1
Security update for postgresql15

SUSE-SU-2025:03005-1
Security update for postgresql16

SUSE-SU-2025:03004-1
Security update for postgresql15

SUSE-SU-2025:03003-1
Security update for postgresql13

SUSE-SU-2025:02995-1
Security update for postgresql17

SUSE-SU-2025:02994-1
Security update for postgresql13

SUSE-SU-2025:02987-1
Security update for postgresql17

SUSE-SU-2025:02986-1
Security update for postgresql17

SUSE-SU-2025:02981-1
Security update for postgresql16

SUSE-SU-2025:02980-1
Security update for postgresql16
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
---|---|---|---|---|
GHSA-cqj3-wjpm-fjvp PostgreSQL optimizer statistics allow a user to read sampled data within a view that the user cannot access. Separately, statistics allow a user to read sampled data that a row security policy intended to hide. PostgreSQL maintains statistics for tables by sampling data available in columns; this data is consulted during the query planning process. Prior to this release, a user could craft a leaky operator that bypassed view access control lists (ACLs) and bypassed row security policies in partitioning or table inheritance hierarchies. Reachable statistics data notably included histograms and most-common-values lists. CVE-2017-7484 and CVE-2019-10130 intended to close this class of vulnerability, but this gap remained. Versions before PostgreSQL 17.6, 16.10, 15.14, 14.19, and 13.22 are affected. | CVSS3: 3.1 | 0% Низкий | 21 день назад | |
![]() | CVE-2025-8713 PostgreSQL optimizer statistics allow a user to read sampled data within a view that the user cannot access. Separately, statistics allow a user to read sampled data that a row security policy intended to hide. PostgreSQL maintains statistics for tables by sampling data available in columns; this data is consulted during the query planning process. Prior to this release, a user could craft a leaky operator that bypassed view access control lists (ACLs) and bypassed row security policies in partitioning or table inheritance hierarchies. Reachable statistics data notably included histograms and most-common-values lists. CVE-2017-7484 and CVE-2019-10130 intended to close this class of vulnerability, but this gap remained. Versions before PostgreSQL 17.6, 16.10, 15.14, 14.19, and 13.22 are affected. | CVSS3: 3.1 | 0% Низкий | 21 день назад |
![]() | CVE-2025-8713 PostgreSQL optimizer statistics allow a user to read sampled data within a view that the user cannot access. Separately, statistics allow a user to read sampled data that a row security policy intended to hide. PostgreSQL maintains statistics for tables by sampling data available in columns; this data is consulted during the query planning process. Prior to this release, a user could craft a leaky operator that bypassed view access control lists (ACLs) and bypassed row security policies in partitioning or table inheritance hierarchies. Reachable statistics data notably included histograms and most-common-values lists. CVE-2017-7484 and CVE-2019-10130 intended to close this class of vulnerability, but this gap remained. Versions before PostgreSQL 17.6, 16.10, 15.14, 14.19, and 13.22 are affected. | CVSS3: 3.1 | 0% Низкий | 21 день назад |
![]() | CVE-2025-8713 PostgreSQL optimizer statistics allow a user to read sampled data within a view that the user cannot access. Separately, statistics allow a user to read sampled data that a row security policy intended to hide. PostgreSQL maintains statistics for tables by sampling data available in columns; this data is consulted during the query planning process. Prior to this release, a user could craft a leaky operator that bypassed view access control lists (ACLs) and bypassed row security policies in partitioning or table inheritance hierarchies. Reachable statistics data notably included histograms and most-common-values lists. CVE-2017-7484 and CVE-2019-10130 intended to close this class of vulnerability, but this gap remained. Versions before PostgreSQL 17.6, 16.10, 15.14, 14.19, and 13.22 are affected. | CVSS3: 3.1 | 0% Низкий | 21 день назад |
CVE-2025-8713 PostgreSQL optimizer statistics allow a user to read sampled data with ... | CVSS3: 3.1 | 0% Низкий | 21 день назад | |
![]() | BDU:2025-09827 Уязвимость компонента core server системы управления базами данных PostgreSQL, позволяющая нарушителю обойти ограничения безопасности ACL и получить несанкционированный доступ к защищаемой информации | CVSS3: 3.1 | 0% Низкий | 23 дня назад |
![]() | SUSE-SU-2025:03031-1 Security update for postgresql14 | 6 дней назад | ||
![]() | SUSE-SU-2025:03030-1 Security update for postgresql15 | 6 дней назад | ||
![]() | SUSE-SU-2025:03020-1 Security update for postgresql14 | 6 дней назад | ||
![]() | SUSE-SU-2025:03019-1 Security update for postgresql14 | 6 дней назад | ||
![]() | SUSE-SU-2025:03018-1 Security update for postgresql15 | 6 дней назад | ||
![]() | SUSE-SU-2025:03005-1 Security update for postgresql16 | 8 дней назад | ||
![]() | SUSE-SU-2025:03004-1 Security update for postgresql15 | 8 дней назад | ||
![]() | SUSE-SU-2025:03003-1 Security update for postgresql13 | 8 дней назад | ||
![]() | SUSE-SU-2025:02995-1 Security update for postgresql17 | 8 дней назад | ||
![]() | SUSE-SU-2025:02994-1 Security update for postgresql13 | 8 дней назад | ||
![]() | SUSE-SU-2025:02987-1 Security update for postgresql17 | 9 дней назад | ||
![]() | SUSE-SU-2025:02986-1 Security update for postgresql17 | 9 дней назад | ||
![]() | SUSE-SU-2025:02981-1 Security update for postgresql16 | 10 дней назад | ||
![]() | SUSE-SU-2025:02980-1 Security update for postgresql16 | 10 дней назад |
Уязвимостей на страницу