Severity
7.5HIGHNVD
EPSS
1.3%
top 20.32%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMay 12
Latest updateAug 14

Description

It was found that some selectivity estimation functions in PostgreSQL before 9.2.21, 9.3.x before 9.3.17, 9.4.x before 9.4.12, 9.5.x before 9.5.7, and 9.6.x before 9.6.3 did not check user privileges before providing information from pg_statistic, possibly leaking information. An unprivileged attacker could use this flaw to steal some information from tables they are otherwise not allowed to access.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:NExploitability: 3.9 | Impact: 3.6

Affected Packages4 packages

CVEListV5postgresql/postgresql1717.6+4
Alpinepostgresql/postgresql< 9.6.3-r0+11
NVDpostgresql/postgresql9.2.20+39

🔴Vulnerability Details

3
GHSA
GHSA-pwf5-pc7m-6hp4: It was found that some selectivity estimation functions in PostgreSQL before 92022-05-14
CVEList
CVE-2017-7484: It was found that some selectivity estimation functions in PostgreSQL before 92017-05-12
OSV
CVE-2017-7484: It was found that some selectivity estimation functions in PostgreSQL before 92017-05-12

📋Vendor Advisories

2
Red Hat
postgresql: PostgreSQL optimizer statistics can expose sampled data within a view, partition, or child table2025-08-14
Red Hat
postgresql: Selectivity estimators bypass SELECT privilege checks2017-05-11

💬Community

4
Bugzilla
CVE-2017-7484 CVE-2017-7485 CVE-2017-7486 mingw-postgresql: various flaws [fedora-all]2017-05-11
Bugzilla
CVE-2017-7484 CVE-2017-7485 CVE-2017-7486 postgresql: various flaws [fedora-all]2017-05-11
Bugzilla
CVE-2017-7484 CVE-2017-7485 CVE-2017-7486 mingw-postgresql: various flaws [epel-7]2017-05-11
Bugzilla
CVE-2017-7484 postgresql: Selectivity estimators bypass SELECT privilege checks2017-05-04
CVE-2017-7484 — Improper Authorization in Postgresql | cvebase