CVE-2017-15099
published 2017-11-22CVE-2017-15099: INSERT ... ON CONFLICT DO UPDATE commands in PostgreSQL 10.x before 10.1, 9.6.x before 9.6.6, and 9.5.x before 9.5.10 disclose table contents that the invoker…
PriorityP339medium6.5CVSS 3.0
AVNACLPRLUINSUCHINAN
EPSS
6.32%
92.9th percentile
INSERT ... ON CONFLICT DO UPDATE commands in PostgreSQL 10.x before 10.1, 9.6.x before 9.6.6, and 9.5.x before 9.5.10 disclose table contents that the invoker lacks privilege to read. These exploits affect only tables where the attacker lacks full read access but has both INSERT and UPDATE privileges. Exploits bypass row level security policies and lack of SELECT privilege.
Affected
30 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| postgresql | postgresql | — | — |
| postgresql | postgresql | — | — |
| postgresql | postgresql | — | — |
| postgresql | postgresql | — | — |
| postgresql | postgresql | — | — |
| postgresql | postgresql | — | — |
| postgresql | postgresql | — | — |
| postgresql | postgresql | — | — |
| postgresql | postgresql | — | — |
| postgresql | postgresql | — | — |
| postgresql | postgresql | — | — |
| postgresql | postgresql | — | — |
| postgresql | postgresql | — | — |
| postgresql | postgresql | — | — |
| postgresql | postgresql | — | — |
| postgresql | postgresql | — | — |
| postgresql | postgresql | — | — |
| postgresql | postgresql | >= 0 < 10.1-r0 | 10.1-r0 |
| postgresql | postgresql | >= 0 < 10.1-r0 | 10.1-r0 |
| postgresql | postgresql | >= 0 < 10.1-r0 | 10.1-r0 |
| postgresql | postgresql | >= 0 < 10.1-r0 | 10.1-r0 |
| postgresql | postgresql | >= 0 < 10.1-r0 | 10.1-r0 |
| postgresql | postgresql | >= 0 < 9.5.10-r0 | 9.5.10-r0 |
| postgresql | postgresql | >= 0 < 9.6.6-r0 | 9.6.6-r0 |
CVSS provenance
nvdv3.06.5MEDIUMCVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
nvdv2.04.0MEDIUMAV:N/AC:L/Au:S/C:P/I:N/A:N
osv6.5MEDIUM
vendor_ubuntu8.1HIGH
vendor_redhat6.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
PostgreSQL vulnerabilities
vendor_ubuntu·2017-11-14·CVSS 8.1
CVE-2017-15098 [HIGH] PostgreSQL vulnerabilities
Title: PostgreSQL vulnerabilities
Summary: Several security issues were fixed in PostgreSQL.
David Rowley discovered that PostgreSQL incorrectly handled memory when
processing certain JSON functions. A remote attacker could possibly use
this issue to obtain sensitive information. (CVE-2017-15098)
Dean Rasheed discovered that PostgreSQL incorrectly enforced SELECT
privileges when processing INSERT ... ON CONFLICT DO UPDATE commands. A
remote attacker could possibly use this issue to obtain sensitive
information. This issue only affected Ubuntu 16.04 LTS, Ubuntu 17.04 and
Ubuntu 17.10.
Instructions: This update uses a new upstream release, which includes additional bug
fixes. After a standard system update you need to restart PostgreSQL to
make all the necessary changes.
Red Hat
postgresql: INSERT ... ON CONFLICT DO UPDATE fails to enforce SELECT privileges
vendor_redhat·2017-11-09·CVSS 6.5
CVE-2017-15099 [MEDIUM] CWE-200 postgresql: INSERT ... ON CONFLICT DO UPDATE fails to enforce SELECT privileges
postgresql: INSERT ... ON CONFLICT DO UPDATE fails to enforce SELECT privileges
INSERT ... ON CONFLICT DO UPDATE commands in PostgreSQL 10.x before 10.1, 9.6.x before 9.6.6, and 9.5.x before 9.5.10 disclose table contents that the invoker lacks privilege to read. These exploits affect only tables where the attacker lacks full read access but has both INSERT and UPDATE privileges. Exploits bypass row level security policies and lack of SELECT privilege.
Statement: This issue affects the versions of rh-postgresql95-postgresql, and rh-postgresql96-postgresql as shipped with Red Hat Software Collections 3. Red Hat Product Security has rated this issue as having Low security impact. A future update may address this issue. For additional information, refer to the Issue Severity Classification:
GHSA
GHSA-pcph-v7q2-77cx: INSERT
ghsa_unreviewed·2022-05-14
CVE-2017-15099 [MEDIUM] CWE-200 GHSA-pcph-v7q2-77cx: INSERT
INSERT ... ON CONFLICT DO UPDATE commands in PostgreSQL 10.x before 10.1, 9.6.x before 9.6.6, and 9.5.x before 9.5.10 disclose table contents that the invoker lacks privilege to read. These exploits affect only tables where the attacker lacks full read access but has both INSERT and UPDATE privileges. Exploits bypass row level security policies and lack of SELECT privilege.
OSV
CVE-2017-15099: INSERT
osv·2017-11-22·CVSS 6.5
CVE-2017-15099 [MEDIUM] CVE-2017-15099: INSERT
INSERT ... ON CONFLICT DO UPDATE commands in PostgreSQL 10.x before 10.1, 9.6.x before 9.6.6, and 9.5.x before 9.5.10 disclose table contents that the invoker lacks privilege to read. These exploits affect only tables where the attacker lacks full read access but has both INSERT and UPDATE privileges. Exploits bypass row level security policies and lack of SELECT privilege.
No detection rules found.
No public exploits indexed.
http://www.securityfocus.com/bid/101781http://www.securitytracker.com/id/1039752https://access.redhat.com/errata/RHSA-2018:2511https://access.redhat.com/errata/RHSA-2018:2566https://www.debian.org/security/2017/dsa-4028https://www.postgresql.org/about/news/1801/https://www.postgresql.org/support/security/http://www.securityfocus.com/bid/101781http://www.securitytracker.com/id/1039752https://access.redhat.com/errata/RHSA-2018:2511https://access.redhat.com/errata/RHSA-2018:2566https://www.debian.org/security/2017/dsa-4028https://www.postgresql.org/about/news/1801/https://www.postgresql.org/support/security/
2017-11-22
Published