cbcvebase.
CVE-2023-39418
published 2023-08-11

CVE-2023-39418: A vulnerability was found in PostgreSQL with the use of the MERGE command, which fails to test new rows against row security policies defined for UPDATE and…

PriorityP421medium4.3CVSS 3.1
AVNACLPRLUINSUCNILAN
EPSS
0.96%
57.5th percentile
A vulnerability was found in PostgreSQL with the use of the MERGE command, which fails to test new rows against row security policies defined for UPDATE and SELECT. If UPDATE and SELECT policies forbid some rows that INSERT policies do not forbid, a user could store such rows.

Affected

6 ranges
VendorProductVersion rangeFixed in
debiandebian_linux
debianpostgresql-13< postgresql-15 15.5-0+deb12u1 (bookworm)postgresql-15 15.5-0+deb12u1 (bookworm)
debianpostgresql-15< postgresql-15 15.5-0+deb12u1 (bookworm)postgresql-15 15.5-0+deb12u1 (bookworm)
postgresqlpostgresql>= 15.0 < 15.415.4
redhatenterprise_linux
redhatenterprise_linux

CVSS provenance

nvdv3.14.3MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
osv8.8HIGH
vendor_ubuntu7.5HIGH
vendor_debian3.1LOW
vendor_redhat3.1LOW
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.