CVE-2020-1720Improper Authorization in Postgresql

Severity
6.5MEDIUMNVD
CNA3.1
EPSS
0.4%
top 42.43%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMar 17
Latest updateMay 24

Description

A flaw was found in PostgreSQL's "ALTER ... DEPENDS ON EXTENSION", where sub-commands did not perform authorization checks. An authenticated attacker could use this flaw in certain configurations to perform drop objects such as function, triggers, et al., leading to database corruption. This issue affects PostgreSQL versions before 12.2, before 11.7, before 10.12 and before 9.6.17.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:NExploitability: 2.8 | Impact: 3.6

Affected Packages4 packages

NVDpostgresql/postgresql9.69.6.17+3
Alpinepostgresql/postgresql< 11.7-r0+6
CVEListV5red_hat/postgresql4 versions+3

Also affects: Enterprise Linux 8.0

Patches

🔴Vulnerability Details

3
GHSA
GHSA-prcp-93mm-93fm: A flaw was found in PostgreSQL's "ALTER2022-05-24
OSV
CVE-2020-1720: A flaw was found in PostgreSQL's "ALTER2020-03-17
CVEList
CVE-2020-1720: A flaw was found in PostgreSQL's "ALTER2020-03-17

📋Vendor Advisories

4
Red Hat
kernel: memory corruption in Voice over IP nf_conntrack_h323 module2020-06-09
Microsoft
A flaw was found in PostgreSQL's "ALTER ... DEPENDS ON EXTENSION" where sub-commands did not perform authorization checks. An authenticated attacker could use this flaw in certain configurations to pe2020-03-10
Ubuntu
PostgreSQL vulnerability2020-02-18
Red Hat
postgresql: ALTER ... DEPENDS ON EXTENSION is missing authorization checks2020-02-13

💬Community

8
Bugzilla
CVE-2020-27759 ImageMagick: outside the range of representable values of type 'int' at MagickCore/quantize.c2020-11-03
Bugzilla
CVE-2020-1720 mingw-postgresql: postgresql: ALTER ... DEPENDS ON EXTENSION is missing authorization checks [fedora-all]2020-03-11
Bugzilla
CVE-2020-1720 postgresql:11/postgresql: ALTER ... DEPENDS ON EXTENSION is missing authorization checks [fedora-all]2020-03-11
Bugzilla
CVE-2020-1720 postgresql:10/postgresql: ALTER ... DEPENDS ON EXTENSION is missing authorization checks [fedora-all]2020-03-11
Bugzilla
CVE-2020-1720 postgresql:9.6/postgresql: ALTER ... DEPENDS ON EXTENSION is missing authorization checks [fedora-all]2020-03-11