Vulnerability CVE-2021-20229: Information

Description

A flaw was found in PostgreSQL in versions before 13.2. This flaw allows a user with SELECT privilege on one column to craft a special query that returns all columns of the table. The highest threat from this vulnerability is to confidentiality.

Severity: MEDIUM (4.3) Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

Published: Feb. 23, 2021
Modified: June 9, 2021
Error type identifier: CWE-863

Fixed packages

Package name
Branch
Fixed in version
Version from repository
Errata ID
Task #
State
postgresql13sisyphus13.2-alt113.14-alt1ALT-PU-2021-1291-1266168Fixed
postgresql13p1013.2-alt113.14-alt0.p10.1ALT-PU-2021-1291-1266168Fixed
postgresql13c10f113.2-alt113.14-alt0.p10.1ALT-PU-2021-1291-1266168Fixed

References to Advisories, Solutions, and Tools

Hyperlink
Resource
https://bugzilla.redhat.com/show_bug.cgi?id=1925296
  • Issue Tracking
  • Third Party Advisory
https://security.netapp.com/advisory/ntap-20210326-0005/
  • Third Party Advisory
GLSA-202105-32
  • Third Party Advisory
    1. Configuration 1

      cpe:2.3:a:postgresql:postgresql:*:*:*:*:*:*:*:*
      Start including
      13.0
      End excliding
      13.2

      Configuration 2

      cpe:2.3:o:redhat:enterprise_linux:7.0:*:*:*:*:*:*:*

      cpe:2.3:o:redhat:enterprise_linux:8.0:*:*:*:*:*:*:*

      cpe:2.3:a:redhat:software_collections:-:*:*:*:*:*:*:*

      Configuration 3

      cpe:2.3:o:fedoraproject:fedora:33:*:*:*:*:*:*:*