CVE-2019-10130
Summary
| CVE | CVE-2019-10130 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2019-07-30 17:15:00 UTC |
| Updated | 2020-09-30 14:08:00 UTC |
| Description | A vulnerability was found in PostgreSQL versions 11.x up to excluding 11.3, 10.x up to excluding 10.8, 9.6.x up to, excluding 9.6.13, 9.5.x up to, excluding 9.5.17. PostgreSQL maintains column statistics for tables. Certain statistics, such as histograms and lists of most common values, contain values taken from the column. PostgreSQL does not evaluate row security policies before consulting those statistics during query planning; an attacker can exploit this to read the most common values of certain columns. Affected columns are those for which the attacker has SELECT privilege and for which, in an ordinary query, row-level security prunes the set of rows visible to the attacker. |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|
| PostgreSQL: Multiple vulnerabilities (GLSA 202003-03) — Gentoo security |
GENTOO |
security.gentoo.org |
Third Party Advisory |
| PostgreSQL: PostgreSQL 11.3, 10.8, 9.6.13, 9.5.17, and 9.4.22 Released! |
MISC |
www.postgresql.org |
Vendor Advisory |
| 1707109 – (CVE-2019-10130) CVE-2019-10130 postgresql: Selectivity estimators bypass row security policies |
CONFIRM |
bugzilla.redhat.com |
Issue Tracking, Third Party Advisory |
| [security-announce] openSUSE-SU-2020:1227-1: moderate: Security update f |
SUSE |
lists.opensuse.org |
Mailing List, Third Party Advisory |
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 159270 Oracle Enterprise Linux Security Update for rh-postgresql10-postgresql (ELSA-2021-9290)
- 500535 Alpine Linux Security Update for postgresql
- 502003 Alpine Linux Security Update for postgresql14
- 502769 Alpine Linux Security Update for postgresql15
- 504302 Alpine Linux Security Update for postgresql14
- 940299 AlmaLinux Security Update for postgresql:9.6 (ALSA-2020:5619)