Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:12538
HistoryJan 15, 2019 - 9:18 a.m.

Information Disclosure

2019-01-1509:18:19
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
9

0.005 Low

EPSS

Percentile

75.3%

rh-postgresql95-postgresql is vulnerable to information disclosure attacks. The vulnerability exists as it was found that some selectivity estimation functions in PostgreSQL before 9.2.21, 9.3.x before 9.3.17, 9.4.x before 9.4.12, 9.5.x before 9.5.7, and 9.6.x before 9.6.3 did not check user privileges before providing information from pg_statistic, possibly leaking information. An unprivileged attacker could use this flaw to steal some information from tables they are otherwise not allowed to access.