CVE-2021-20229
published 2021-02-23CVE-2021-20229: A flaw was found in PostgreSQL in versions before 13.2. This flaw allows a user with SELECT privilege on one column to craft a special query that returns all…
PriorityP422medium4.3CVSS 3.1
AVNACLPRLUINSUCLINAN
EPSS
1.47%
70.8th percentile
A flaw was found in PostgreSQL in versions before 13.2. This flaw allows a user with SELECT privilege on one column to craft a special query that returns all columns of the table. The highest threat from this vulnerability is to confidentiality.
Affected
14 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | postgresql-13 | < postgresql-13 13.2-1 (bullseye) | postgresql-13 13.2-1 (bullseye) |
| fedoraproject | fedora | — | — |
| msrc | postgresql-12.7-1.cm1.aarch64.rpm_on_cbl_mariner_1.0_arm | — | — |
| msrc | postgresql-12.7-1.cm1.x86_64.rpm_on_cbl_mariner_1.0_x64 | — | — |
| msrc | postgresql-debuginfo-12.7-1.cm1.aarch64.rpm_on_cbl_mariner_1.0_arm | — | — |
| msrc | postgresql-debuginfo-12.7-1.cm1.x86_64.rpm_on_cbl_mariner_1.0_x64 | — | — |
| msrc | postgresql-devel-12.7-1.cm1.aarch64.rpm_on_cbl_mariner_1.0_arm | — | — |
| msrc | postgresql-devel-12.7-1.cm1.x86_64.rpm_on_cbl_mariner_1.0_x64 | — | — |
| msrc | postgresql-libs-12.7-1.cm1.aarch64.rpm_on_cbl_mariner_1.0_arm | — | — |
| msrc | postgresql-libs-12.7-1.cm1.x86_64.rpm_on_cbl_mariner_1.0_x64 | — | — |
| postgresql | postgresql | — | — |
| postgresql | postgresql | >= 13.0 < 13.2 | 13.2 |
| redhat | enterprise_linux | — | — |
| redhat | enterprise_linux | — | — |
CVSS provenance
nvdv3.14.3MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
nvdv2.04.0MEDIUMAV:N/AC:L/Au:S/C:P/I:N/A:N
osv4.3MEDIUM
vendor_debian4.3MEDIUM
vendor_msrc4.3MEDIUM
vendor_redhat4.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
postgresql: single-column SELECT privilege enables reading all columns
vendor_redhat·2021-02-11·CVSS 4.3
CVE-2021-20229 [MEDIUM] CWE-863 postgresql: single-column SELECT privilege enables reading all columns
postgresql: single-column SELECT privilege enables reading all columns
A flaw was found in PostgreSQL in versions before 13.2. This flaw allows a user with SELECT privilege on one column to craft a special query that returns all columns of the table. The highest threat from this vulnerability is to confidentiality.
A flaw was found in PostgreSQL. This flaw allows a user with SELECT privilege on one column to craft a special query that returns all columns of the table. The highest threat from this vulnerability is to confidentiality.
Package: postgresql (Red Hat build of Quarkus) - Not affected
Package: postgresql (Red Hat Decision Manager 7) - Not affected
Package: postgresql (Red Hat Enterprise Linux 6) - Out of support scope
Package: postgresql (Red Hat Enterprise Linux 7) - Fix de
Microsoft
A flaw was found in PostgreSQL in versions before 13.2. This flaw allows a user with SELECT privilege on one column to craft a special query that returns all columns of the table. The highest threat f
vendor_msrc·2021-02-09·CVSS 4.3
CVE-2021-20229 [MEDIUM] CWE-863 A flaw was found in PostgreSQL in versions before 13.2. This flaw allows a user with SELECT privilege on one column to craft a special query that returns all columns of the table. The highest threat f
A flaw was found in PostgreSQL in versions before 13.2. This flaw allows a user with SELECT privilege on one column to craft a special query that returns all columns of the table. The highest threat from this vulnerability is to confidentiality.
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparency in this work which is why we began publishing CSAF/VEX in October 2025. See this blog post for more information. If impact to addition
Debian
CVE-2021-20229: postgresql-13 - A flaw was found in PostgreSQL in versions before 13.2. This flaw allows a user ...
vendor_debian·2021·CVSS 4.3
CVE-2021-20229 [MEDIUM] CVE-2021-20229: postgresql-13 - A flaw was found in PostgreSQL in versions before 13.2. This flaw allows a user ...
A flaw was found in PostgreSQL in versions before 13.2. This flaw allows a user with SELECT privilege on one column to craft a special query that returns all columns of the table. The highest threat from this vulnerability is to confidentiality.
Scope: local
bullseye: resolved (fixed in 13.2-1)
GHSA
Incorrect Authorization in PostgreSQL
ghsa_unreviewed·2022-02-15
CVE-2021-20229 [MEDIUM] CWE-863 Incorrect Authorization in PostgreSQL
Incorrect Authorization in PostgreSQL
A flaw was found in PostgreSQL in versions before 13.2, before 12.6, before 11.11, before 10.16, before 9.6.21 and before 9.5.25. This flaw allows a user with SELECT privilege on one column to craft a special query that returns all columns of the table. The highest threat from this vulnerability is to confidentiality.
OSV
CVE-2021-20229: A flaw was found in PostgreSQL in versions before 13
osv·2021-02-23·CVSS 4.3
CVE-2021-20229 [MEDIUM] CVE-2021-20229: A flaw was found in PostgreSQL in versions before 13
A flaw was found in PostgreSQL in versions before 13.2. This flaw allows a user with SELECT privilege on one column to craft a special query that returns all columns of the table. The highest threat from this vulnerability is to confidentiality.
No detection rules found.
No public exploits indexed.
2021-02-23
Published