CVE-2020-1720
Summary
| CVE | CVE-2020-1720 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2020-03-17 16:15:00 UTC |
| Updated | 2023-11-07 03:19:00 UTC |
| Description | A flaw was found in PostgreSQL's "ALTER ... DEPENDS ON EXTENSION", where sub-commands did not perform authorization checks. An authenticated attacker could use this flaw in certain configurations to perform drop objects such as function, triggers, et al., leading to database corruption. This issue affects PostgreSQL versions before 12.2, before 11.7, before 10.12 and before 9.6.17. |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|
| 1798852 – (CVE-2020-1720) CVE-2020-1720 postgresql: ALTER ... DEPENDS ON EXTENSION is missing authorization checks |
CONFIRM |
bugzilla.redhat.com |
Issue Tracking, Patch, Third Party Advisory |
| PostgreSQL: PostgreSQL 12.2, 11.7, 10.12, 9.6.17, 9.5.21, and 9.4.26 Released! |
MISC |
www.postgresql.org |
Release Notes, Vendor Advisory |
| [security-announce] openSUSE-SU-2020:1227-1: moderate: Security update f |
SUSE |
lists.opensuse.org |
|
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 159270 Oracle Enterprise Linux Security Update for rh-postgresql10-postgresql (ELSA-2021-9290)
- 377113 Alibaba Cloud Linux Security Update for postgresql:12 (ALINUX3-SA-2021:0017)
- 500538 Alpine Linux Security Update for postgresql
- 502006 Alpine Linux Security Update for postgresql14
- 502160 Alpine Linux Security Update for postgresql12
- 502772 Alpine Linux Security Update for postgresql15
- 504305 Alpine Linux Security Update for postgresql14
- 900047 CBL-Mariner Linux Security Update for postgresql 12.1
- 903369 Common Base Linux Mariner (CBL-Mariner) Security Update for postgresql (1892)
- 940130 AlmaLinux Security Update for postgresql:12 (ALSA-2020:5620)
- 940299 AlmaLinux Security Update for postgresql:9.6 (ALSA-2020:5619)
- 960242 Rocky Linux Security Update for postgresql:12 (RLSA-2020:5620)