KLA12088
Multiple vulnerabilities in PostgreSQL

Updated: 02/16/2021
Detect date
?
02/11/2021
Severity
?
Warning
Description

Multiple vulnerabilities were found in PostgreSQL. Malicious users can exploit these vulnerabilities to bypass security restrictions, obtain sensitive information.

Below is a complete list of vulnerabilities:

  1. A security bypass vulnerability in SELECT privilege can be exploited to bypass security restrictions.
  2. A security vulnerability vulnerability in SELECT privilege can be exploited via special crafted query to bypass security restrictions and obtain sensitive information.
Affected products

PostgreSQL 9.5 earlier than 9.5.25
PostgreSQL 9.6 earlier than 9.6.21
PostgreSQL 10 earlier than 10.16
PostgreSQL 11 earlier than 11.11
PostgreSQL 12 earlier than 12.6
PostgreSQL 13 earlier than 13.2

Solution

Update to the latest version
Download PostgreSQL

Original advisories

PostgreSQL News

Impacts
?
OSI 
[?]

SB 
[?]
Related products
PostgreSQL
CVE-IDS
?
CVE-2021-33933.5Warning
CVE-2021-202294.0Warning
Find out the statistics of the vulnerabilities spreading in your region