Lucene search

K
cvelistRedhatCVELIST:CVE-2021-32029
HistoryOct 08, 2021 - 4:44 p.m.

CVE-2021-32029

2021-10-0816:44:22
CWE-200
redhat
www.cve.org
1

7.5 High

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

43.0%

A flaw was found in postgresql. Using an UPDATE … RETURNING command on a purpose-crafted table, an authenticated database user could read arbitrary bytes of server memory. The highest threat from this vulnerability is to data confidentiality.

CNA Affected

[
  {
    "product": "postgresql",
    "vendor": "n/a",
    "versions": [
      {
        "status": "affected",
        "version": "postgresql 13.3, postgresql 12.7, postgresql 11.12"
      }
    ]
  }
]