CVE-2021-3393

An information leak was discovered in postgresql in versions before 13.2, before 12.6 and before 11.11. A user having UPDATE permission but not SELECT permission to a particular column could craft queries which, under some circumstances, might disclose values from that column in error messages. An attacker could use this flaw to obtain information stored in a column they are allowed to write but not read.
References
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:postgresql:postgresql:*:*:*:*:*:*:*:*
cpe:2.3:a:postgresql:postgresql:*:*:*:*:*:*:*:*
cpe:2.3:a:postgresql:postgresql:*:*:*:*:*:*:*:*

Configuration 2 (hide)

OR cpe:2.3:a:redhat:software_collections:-:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux:8.0:*:*:*:*:*:*:*

History

04 Jun 2021, 19:04

Type Values Removed Values Added
References (CONFIRM) https://security.netapp.com/advisory/ntap-20210507-0006/ - (CONFIRM) https://security.netapp.com/advisory/ntap-20210507-0006/ - Third Party Advisory
References (GENTOO) https://security.gentoo.org/glsa/202105-32 - (GENTOO) https://security.gentoo.org/glsa/202105-32 - Third Party Advisory

26 May 2021, 12:15

Type Values Removed Values Added
References
  • (CONFIRM) https://security.netapp.com/advisory/ntap-20210507-0006/ -
  • (GENTOO) https://security.gentoo.org/glsa/202105-32 -

07 Apr 2021, 12:47

Type Values Removed Values Added
References (MISC) https://bugzilla.redhat.com/show_bug.cgi?id=1924005 - (MISC) https://bugzilla.redhat.com/show_bug.cgi?id=1924005 - Issue Tracking, Third Party Advisory
CVSS v2 : unknown
v3 : unknown
v2 : 3.5
v3 : 4.3
CPE cpe:2.3:a:postgresql:postgresql:*:*:*:*:*:*:*:*
cpe:2.3:a:redhat:software_collections:-:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux:8.0:*:*:*:*:*:*:*

01 Apr 2021, 14:19

Type Values Removed Values Added
New CVE

Information

Published : 2021-04-01 14:15

Updated : 2023-12-10 13:55


NVD link : CVE-2021-3393

Mitre link : CVE-2021-3393

CVE.ORG link : CVE-2021-3393


JSON object : View

Products Affected

redhat

  • software_collections
  • enterprise_linux

postgresql

  • postgresql
CWE
CWE-209

Generation of Error Message Containing Sensitive Information