Bug 2228112 (CVE-2023-39418)
| Summary: | CVE-2023-39418 postgresql: MERGE fails to enforce UPDATE or SELECT row security policies | ||
|---|---|---|---|
| Product: | [Other] Security Response | Reporter: | TEJ RATHI <trathi> |
| Component: | vulnerability | Assignee: | Nobody <nobody> |
| Status: | NEW --- | QA Contact: | |
| Severity: | low | Docs Contact: | |
| Priority: | low | ||
| Version: | unspecified | CC: | adudiak, caswilli, fjansen, fjanus, hhorak, hkataria, jburrell, jorton, kaycoth, kshier, nweather, pkubat, praiskup, psegedy, security-response-team, stcannon, tsasak, yguenane |
| Target Milestone: | --- | Keywords: | Security |
| Target Release: | --- | ||
| Hardware: | All | ||
| OS: | Linux | ||
| Whiteboard: | |||
| Fixed In Version: | postgresql 15.4 | Doc Type: | If docs needed, set a value |
| Doc Text: |
A vulnerability was found in PostgreSQL with the use of the MERGE command, which fails to test new rows against row security policies defined for UPDATE and SELECT. If UPDATE and SELECT policies forbid some rows that INSERT policies do not forbid, a user could store such rows.
|
Story Points: | --- |
| Clone Of: | Environment: | ||
| Last Closed: | Type: | --- | |
| Regression: | --- | Mount Type: | --- |
| Documentation: | --- | CRM: | |
| Verified Versions: | Category: | --- | |
| oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
| Cloudforms Team: | --- | Target Upstream Version: | |
| Embargoed: | |||
| Bug Depends On: | 2228113, 2228114 | ||
| Bug Blocks: | 2228105 | ||
|
Description
TEJ RATHI
2023-08-01 12:31:51 UTC
This CVE is now public - https://www.postgresql.org/support/security/CVE-2023-39418 |