CVE-2021-3393
Summary
| CVE | CVE-2021-3393 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2021-04-01 14:15:00 UTC |
| Updated | 2021-06-04 19:04:00 UTC |
| Description | An information leak was discovered in postgresql in versions before 13.2, before 12.6 and before 11.11. A user having UPDATE permission but not SELECT permission to a particular column could craft queries which, under some circumstances, might disclose values from that column in error messages. An attacker could use this flaw to obtain information stored in a column they are allowed to write but not read. |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|
| PostgreSQL: Multiple vulnerabilities (GLSA 202105-32) — Gentoo security |
GENTOO |
security.gentoo.org |
|
| 1924005 – (CVE-2021-3393) CVE-2021-3393 postgresql: Partition constraint violation errors leak values of denied columns |
MISC |
bugzilla.redhat.com |
|
| CVE-2021-3393 PostgreSQL Vulnerability in NetApp Products | NetApp Product Security |
CONFIRM |
security.netapp.com |
|
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 159268 Oracle Enterprise Linux Security Update for postgresql:12 (ELSA-2021-2372)
- 179731 Debian Security Update for postgresql-13postgresql-11 (CVE-2021-3393)
- 239383 Red Hat Update for postgresql:12 (RHSA-2021:2372)
- 239437 Red Hat Update for rh-postgresql12-postgresql (RHSA-2021:2394)
- 239442 Red Hat Update for postgresql:12 (RHSA-2021:2389)
- 356175 Amazon Linux Security Advisory for postgresql : ALASPOSTGRESQL12-2023-004
- 500541 Alpine Linux Security Update for postgresql
- 501469 Alpine Linux Security Update for postgresql
- 501992 Alpine Linux Security Update for postgresql13
- 502009 Alpine Linux Security Update for postgresql14
- 502775 Alpine Linux Security Update for postgresql15
- 504308 Alpine Linux Security Update for postgresql14
- 710082 Gentoo Linux PostgreSQL Multiple vulnerabilities (GLSA 202105-32)
- 750053 SUSE Enterprise Linux Security Update for postgresql12 (SUSE-SU-2021:1783-1)
- 750311 OpenSUSE Security Update for postgresql12 (openSUSE-SU-2021:0423-1)
- 940413 AlmaLinux Security Update for postgresql:12 (ALSA-2021:2372)
- 960093 Rocky Linux Security Update for postgresql:12 (RLSA-2021:2372)