• CVE-2023-39418

发布时间: 2025年4月13日

修改时间: 2025年4月13日

概要

A vulnerability was found in PostgreSQL with the use of the MERGE command, which fails to test new rows against row security policies defined for UPDATE and SELECT. If UPDATE and SELECT policies forbid some rows that INSERT policies do not forbid, a user could store such rows.

CVSS v3 指标

NVD openEuler
CVSS评分 4.3 4.3
Attack Vector Network Network
Attack Complexity Low Low
Privileges Required Low Low
User Interaction None None
Scope Unchanged Unchanged
Confidentiality None None
Integrity Low Low
Availability None None

安全公告

公告名 概要 发布时间
KylinSec-SA-2025-2308 A vulnerability was found in PostgreSQL with the use of the MERGE command, which fails to test new rows against row security policies defined for UPDATE and SELECT. If UPDATE and SELECT policies forbid some rows that INSERT policies do not forbid, a user could store such rows. 2025年4月20日

影响产品

产品 状态
KY3.4-5A postgresql-13 Unaffected
KY3.5.3 postgresql-13 Unaffected
V6 postgresql-13 Unaffected