PostgreSQL versions 8.4 - 9.6 are vulnerable to information leak in pg_user_mappings view which discloses foreign server passwords to any user having USAGE privilege on the associated foreign server.
OS | Version | Architecture | Package | Version | Filename |
---|---|---|---|---|---|
Debian | 9 | all | postgresql-9.6 | < 9.6.17-0+deb9u1 | postgresql-9.6_9.6.17-0+deb9u1_all.deb |