Korean
<< Back
VID 25348
Severity 30
Port 5432
Protocol TCP
Class DB
Detailed Description The version of PostgreSQL installed on the remote host is 11 prior to 11.11, 12 prior to 12.6, or 13 prior to 13.2. As such, it is potentially affected by multiple vulnerabilities :

- An information leak was discovered in postgresql in versions before 13.2, before 12.6 and before 11.11.
A user having UPDATE permission but not SELECT permission to a particular column could craft queries which, under some circumstances, might disclose values from that column in error messages. An attacker could use this flaw to obtain information stored in a column they are allowed to write but not read.
(CVE-2021-3393)

- A flaw was found in PostgreSQL in versions before 13.2, before 12.6, before 11.11. This flaw allows a user with SELECT privilege on one column to craft a special query that returns all columns of the table.
The highest threat from this vulnerability is to confidentiality (CVE-2021-20229)

* References:
https://www.postgresql.org/about/news/postgresql-132-126-1111-1016-9621-and-9525-released-2165/
https://access.redhat.com/security/cve/CVE-2021-20229
https://access.redhat.com/security/cve/CVE-2021-3393

* Platforms Affected:
PostgreSQL 11.x prior to 11.11
Any operating system Any version
Recommendation Upgrade to the latest version of PostgreSQL (11.11 or later), available from the PostgreSQL Web page at http://www.postgresql.org/download/
Related URL CVE-2021-3393,CVE-2021-20229 (CVE)
Related URL (SecurityFocus)
Related URL (ISS)