CVE-2021-20229
Summary
| CVE | CVE-2021-20229 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2021-02-23 18:15:00 UTC |
| Updated | 2021-06-09 15:01:00 UTC |
| Description | A flaw was found in PostgreSQL in versions before 13.2. This flaw allows a user with SELECT privilege on one column to craft a special query that returns all columns of the table. The highest threat from this vulnerability is to confidentiality. |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|
| CVE-2021-20229 PostgreSQL Vulnerability in NetApp Products | NetApp Product Security |
CONFIRM |
security.netapp.com |
|
| 1925296 – (CVE-2021-20229) CVE-2021-20229 postgresql: single-column SELECT privilege enables reading all columns |
MISC |
bugzilla.redhat.com |
Issue Tracking, Third Party Advisory |
| PostgreSQL: Multiple vulnerabilities (GLSA 202105-32) — Gentoo security |
GENTOO |
security.gentoo.org |
|
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 180318 Debian Security Update for postgresql-13 (CVE-2021-20229)
- 500541 Alpine Linux Security Update for postgresql
- 501469 Alpine Linux Security Update for postgresql
- 501992 Alpine Linux Security Update for postgresql13
- 502009 Alpine Linux Security Update for postgresql14
- 502775 Alpine Linux Security Update for postgresql15
- 504308 Alpine Linux Security Update for postgresql14
- 710082 Gentoo Linux PostgreSQL Multiple vulnerabilities (GLSA 202105-32)
- 900020 CBL-Mariner Linux Security Update for postgresql 12.5
- 903508 Common Base Linux Mariner (CBL-Mariner) Security Update for postgresql (3909)