V
Scaner-VS
HomeCatalogSourcesCWECAPECATT&CKMitigationsDocs
CVE-2023-39418
AST
Low

A vulnerability was found in PostgreSQL with the use of the MERGE command, which fails to test new rows against row security policies defin…

CVSS
3.1
Low
EPSS
0.00
p63
Published
2023-01-01
Updated
2023-01-01
Description

A vulnerability was found in PostgreSQL with the use of the MERGE command, which fails to test new rows against row security policies defined for UPDATE and SELECT. If UPDATE and SELECT policies forbid some rows that INSERT policies do not forbid, a user could store such rows.

Tags · CWE
CWE-1220
CAPEC-1
CAPEC-180
Affected products
PostgresqlPostgresqlPostgresqlPostgresqlPostgresql-10Postgresql-11Postgresql-12Postgresql-12Postgresql-13Postgresql-14Postgresql-15Postgresql-15Postgresql-15Postgresql-15Postgresql-15Postgresql-15Postgresql-15Postgresql-9.1Postgresql-9.3Postgresql-9.5
CVSS vector
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:N
Timeline
2023-01-01
Published
2023-01-01
Updated
CVSS 3.1 breakdown
Attack Vector
AV: N
Network (N)
Attack Complexity
AC: H
High (H)
Privileges Required
PR: L
Low (L)
User Interaction
UI: N
None (N)
Scope
S: U
Unchanged (U)
Confidentiality Impact
C: N
None (N)
Integrity Impact
I: L
Low (L)
Availability Impact
A: N
None (N)
Exploit indicators
EPSS
0.004 · p63
Known exploited (KEV)
No
MITRE ATT&CK
Inferred via CAPEC
Known exploits — Сканер-ВС
No Сканер-ВС checks registered for this vulnerability yet.
Affected software
ProductVendorStatus
postgresqlTracked
postgresqlTracked
postgresqlTracked
postgresqlTracked
postgresql-10Tracked
postgresql-11Tracked
postgresql-12Tracked
postgresql-12Tracked
postgresql-13Tracked
postgresql-14Tracked
postgresql-15Tracked
postgresql-15Tracked
postgresql-15Tracked
postgresql-15Tracked
postgresql-15Tracked
postgresql-15Tracked
postgresql-15Tracked
postgresql-9.1Tracked
postgresql-9.3Tracked
postgresql-9.5Tracked
Source databases
AST
DEB
CVE
RED
UBU
Related vulnerabilities