CVE-2023-39418
LOW severity · CVSS 3.1 · CWE-1220
3.1CVSS LOW
Summary
A vulnerability was found in PostgreSQL with the use of the MERGE command, which fails to test new rows against row security policies defined for UPDATE and SELECT. If UPDATE and SELECT policies forbid some rows that INSERT policies do not forbid, a user could store such rows.
Impact & exploitability
Attack vectorNetwork
Attack complexityHigh
Privileges requiredLow
User interactionNone
Confidentiality impactNone
Integrity impactLow
Availability impactNone
Exploit probability (EPSS)1%
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:N
Affected products we track (1)
Recommendation
Apply the vendor fix in your normal patch cycle. Open any affected product above for its exact safe version.
Official patch: https://bugzilla.redhat.com/show_bug.cgi?id=2228112 ↗
Additional information
- NVD record
- https://bugzilla.redhat.com/show_bug.cgi?id=2228112Patch
- https://git.postgresql.org/gitweb/?p=postgresql.git;a=commitdiff;h=cb2ae5741f2458a474ed3c31458d242e678ff229Patch
- https://www.postgresql.org/support/security/CVE-2023-39418/Advisory
- https://access.redhat.com/errata/RHSA-2023:7785Advisory
- https://access.redhat.com/errata/RHSA-2023:7883Advisory
- https://access.redhat.com/errata/RHSA-2023:7884Advisory
- https://access.redhat.com/errata/RHSA-2023:7885Advisory
- https://access.redhat.com/security/cve/CVE-2023-39418Advisory