cbcvebase.
CVE-2023-2455
published 2023-06-09

CVE-2023-2455: Row security policies disregard user ID changes after inlining; PostgreSQL could permit incorrect policies to be applied in certain cases where role-specific…

medium5.4CVSS 3.1
AVNACLPRLUINSUCLILAN
Row security policies disregard user ID changes after inlining; PostgreSQL could permit incorrect policies to be applied in certain cases where role-specific policies are used and a given query is planned under one role and then executed under other roles. This scenario can happen under security definer functions or when a common user and query is planned initially and then re-used across multiple SET ROLEs. Applying an incorrect policy may permit a user to complete otherwise-forbidden reads and modifications. This affects only databases that have used CREATE POLICY to define a row security policy.

Affected

22 ranges
VendorProductVersion rangeFixed in
debianpostgresql-13< postgresql-13 13.11-0+deb11u1 (bullseye)postgresql-13 13.11-0+deb11u1 (bullseye)
debianpostgresql-13< postgresql-13 13.17-0+deb11u1 (bullseye)postgresql-13 13.17-0+deb11u1 (bullseye)
debianpostgresql-15< postgresql-13 13.11-0+deb11u1 (bullseye)postgresql-13 13.11-0+deb11u1 (bullseye)
debianpostgresql-15< postgresql-13 13.17-0+deb11u1 (bullseye)postgresql-13 13.17-0+deb11u1 (bullseye)
debianpostgresql-17< postgresql-13 13.17-0+deb11u1 (bullseye)postgresql-13 13.17-0+deb11u1 (bullseye)
fedoraprojectfedora
msrccbl_mariner_2.0_arm
msrccbl_mariner_2.0_x64
postgresqlpostgresql
postgresqlpostgresql>= 11.0 < 11.2011.20
postgresqlpostgresql>= 12.0 < 12.2112.21
postgresqlpostgresql>= 12.0 < 12.1512.15
postgresqlpostgresql>= 13.0 < 13.1713.17
postgresqlpostgresql>= 13.0 < 13.1113.11
postgresqlpostgresql>= 14.0 < 14.1414.14
postgresqlpostgresql>= 14.0 < 14.814.8
postgresqlpostgresql>= 15.0 < 15.915.9
postgresqlpostgresql>= 15.0 < 15.315.3
postgresqlpostgresql>= 16.0 < 16.516.5
postgresqlpostgresql>= 17.0 < 17.117.1
redhatenterprise_linux
redhatenterprise_linux

CVSS provenance

nvdv3.15.4MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N
osv7.5HIGH