VID |
25348 |
Severity |
30 |
Port |
5432 |
Protocol |
TCP |
Class |
DB |
Detailed Description |
The version of PostgreSQL installed on the remote host is 11 prior to 11.11, 12 prior to 12.6, or 13 prior to 13.2. As such, it is potentially affected by multiple vulnerabilities :
- An information leak was discovered in postgresql in versions before 13.2, before 12.6 and before 11.11. A user having UPDATE permission but not SELECT permission to a particular column could craft queries which, under some circumstances, might disclose values from that column in error messages. An attacker could use this flaw to obtain information stored in a column they are allowed to write but not read. (CVE-2021-3393)
- A flaw was found in PostgreSQL in versions before 13.2, before 12.6, before 11.11. This flaw allows a user with SELECT privilege on one column to craft a special query that returns all columns of the table. The highest threat from this vulnerability is to confidentiality (CVE-2021-20229)
* References: https://www.postgresql.org/about/news/postgresql-132-126-1111-1016-9621-and-9525-released-2165/ https://access.redhat.com/security/cve/CVE-2021-20229 https://access.redhat.com/security/cve/CVE-2021-3393
* Platforms Affected: PostgreSQL 11.x prior to 11.11 Any operating system Any version |
Recommendation |
Upgrade to the latest version of PostgreSQL (11.11 or later), available from the PostgreSQL Web page at http://www.postgresql.org/download/ |
Related URL |
CVE-2021-3393,CVE-2021-20229 (CVE) |
Related URL |
(SecurityFocus) |
Related URL |
(ISS) |
|