CVE-2021-3393
published 2021-04-01CVE-2021-3393: An information leak was discovered in postgresql in versions before 13.2, before 12.6 and before 11.11. A user having UPDATE permission but not SELECT…
PriorityP421medium4.3CVSS 3.1
AVNACLPRLUINSUCLINAN
EPSS
1.19%
64.4th percentile
An information leak was discovered in postgresql in versions before 13.2, before 12.6 and before 11.11. A user having UPDATE permission but not SELECT permission to a particular column could craft queries which, under some circumstances, might disclose values from that column in error messages. An attacker could use this flaw to obtain information stored in a column they are allowed to write but not read.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | postgresql-13 | < postgresql-13 13.2-1 (bullseye) | postgresql-13 13.2-1 (bullseye) |
| postgresql | postgresql | < 11.11 | 11.11 |
| postgresql | postgresql | — | — |
| postgresql | postgresql | >= 12.0 < 12.6 | 12.6 |
| postgresql | postgresql | >= 13.0 < 13.2 | 13.2 |
| redhat | enterprise_linux | — | — |
CVSS provenance
nvdv3.14.3MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
nvdv2.03.5LOWAV:N/AC:M/Au:S/C:P/I:N/A:N
osv4.3MEDIUM
vendor_debian4.3MEDIUM
vendor_redhat4.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
Generation of Error Message Containing Sensitive Information in postgresql
ghsa_unreviewed·2022-02-15
CVE-2021-3393 [MEDIUM] CWE-209 Generation of Error Message Containing Sensitive Information in postgresql
Generation of Error Message Containing Sensitive Information in postgresql
An information leak was discovered in postgresql in versions before 13.2, before 12.6 and before 11.11. A user having UPDATE permission but not SELECT permission to a particular column could craft queries which, under some circumstances, might disclose values from that column in error messages. An attacker could use this flaw to obtain information stored in a column they are allowed to write but not read.
OSV
CVE-2021-3393: An information leak was discovered in postgresql in versions before 13
osv·2021-04-01·CVSS 4.3
CVE-2021-3393 [MEDIUM] CVE-2021-3393: An information leak was discovered in postgresql in versions before 13
An information leak was discovered in postgresql in versions before 13.2, before 12.6 and before 11.11. A user having UPDATE permission but not SELECT permission to a particular column could craft queries which, under some circumstances, might disclose values from that column in error messages. An attacker could use this flaw to obtain information stored in a column they are allowed to write but not read.
Ubuntu
PostgreSQL vulnerability
vendor_ubuntu·2021-02-15
CVE-2021-3393 PostgreSQL vulnerability
Title: PostgreSQL vulnerability
Summary: PostgreSQL could be made to expose sensitive information.
Heikki Linnakangas discovered that PostgreSQL incorrectly leaked values of
denied columns when handling certain errors. A remote attacker could
possibly use this issue to obtain sensitive information.
Instructions: This update uses a new upstream release, which includes additional bug
fixes. After a standard system update you need to restart PostgreSQL to
make all the necessary changes.
Red Hat
postgresql: Partition constraint violation errors leak values of denied columns
vendor_redhat·2021-02-11·CVSS 4.3
CVE-2021-3393 [MEDIUM] CWE-209 postgresql: Partition constraint violation errors leak values of denied columns
postgresql: Partition constraint violation errors leak values of denied columns
An information leak was discovered in postgresql in versions before 13.2, before 12.6 and before 11.11. A user having UPDATE permission but not SELECT permission to a particular column could craft queries which, under some circumstances, might disclose values from that column in error messages. An attacker could use this flaw to obtain information stored in a column they are allowed to write but not read.
An information leak was discovered in postgresql. A user having UPDATE permission but not SELECT permission to a particular column could craft queries which, under some circumstances, might disclose values from that column in error messages. An attacker could use this flaw to obtain information stored in a c
Debian
CVE-2021-3393: postgresql-13 - An information leak was discovered in postgresql in versions before 13.2, before...
vendor_debian·2021·CVSS 4.3
CVE-2021-3393 [MEDIUM] CVE-2021-3393: postgresql-13 - An information leak was discovered in postgresql in versions before 13.2, before...
An information leak was discovered in postgresql in versions before 13.2, before 12.6 and before 11.11. A user having UPDATE permission but not SELECT permission to a particular column could craft queries which, under some circumstances, might disclose values from that column in error messages. An attacker could use this flaw to obtain information stored in a column they are allowed to write but not read.
Scope: local
bullseye: resolved (fixed in 13.2-1)
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2021-04-01
Published