Lucene search

K
cvelistRedhatCVELIST:CVE-2021-3393
HistoryApr 01, 2021 - 1:46 p.m.

CVE-2021-3393

2021-04-0113:46:02
CWE-209
redhat
www.cve.org
1

4.7 Medium

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

26.9%

An information leak was discovered in postgresql in versions before 13.2, before 12.6 and before 11.11. A user having UPDATE permission but not SELECT permission to a particular column could craft queries which, under some circumstances, might disclose values from that column in error messages. An attacker could use this flaw to obtain information stored in a column they are allowed to write but not read.

CNA Affected

[
  {
    "product": "postgresql",
    "vendor": "n/a",
    "versions": [
      {
        "status": "affected",
        "version": "postgresql 13.2, postgresql 12.6, postgresql 11.11"
      }
    ]
  }
]