A flaw was found in postgresql. Using an INSERT … ON CONFLICT … DO UPDATE command on a purpose-crafted table, an authenticated database user could read arbitrary bytes of server memory. The highest threat from this vulnerability is to data confidentiality.
CPE | Name | Operator | Version |
---|---|---|---|
postgresql | ge | 13.0 | |
postgresql | lt | 13.3 | |
postgresql | ge | 12.0 | |
postgresql | lt | 12.7 | |
postgresql | ge | 10.0 | |
postgresql | lt | 10.17 | |
postgresql | ge | 11.0 | |
postgresql | lt | 11.12 | |
postgresql | ge | 9.6.0 | |
postgresql | lt | 9.6.22 |