cbcvebase.
CVE-2024-10976
published 2024-11-14

CVE-2024-10976: Incomplete tracking in PostgreSQL of tables with row security allows a reused query to view or change different rows from those intended. CVE-2023-2455 and…

PriorityP430medium5.4CVSS 3.1
AVNACLPRLUINSUCLILAN
EPSS
0.79%
52.1th percentile
Incomplete tracking in PostgreSQL of tables with row security allows a reused query to view or change different rows from those intended. CVE-2023-2455 and CVE-2016-2193 fixed most interaction between row security and user ID changes. They missed cases where a subquery, WITH query, security invoker view, or SQL-language function references a table with a row-level security policy. This has the same consequences as the two earlier CVEs. That is to say, it leads to potentially incorrect policies being applied in cases where role-specific policies are used and a given query is planned under one role and then executed under other roles. This scenario can happen under security definer functions or when a common user and query is planned initially and then re-used across multiple SET ROLEs. Applying an incorrect policy may permit a user to complete otherwise-forbidden reads and modifications. This affects only databases that have used CREATE POLICY to define a row security policy. An attacker must tailor an attack to a particular application's pattern of query plan reuse, user ID changes, and role-specific row security policies. Versions before PostgreSQL 17.1, 16.5, 15.9, 14.14, 13.17, and 12.21 are affected.

Affected

13 ranges
VendorProductVersion rangeFixed in
debianpostgresql-13< postgresql-13 13.17-0+deb11u1 (bullseye)postgresql-13 13.17-0+deb11u1 (bullseye)
debianpostgresql-15< postgresql-13 13.17-0+deb11u1 (bullseye)postgresql-13 13.17-0+deb11u1 (bullseye)
debianpostgresql-17< postgresql-13 13.17-0+deb11u1 (bullseye)postgresql-13 13.17-0+deb11u1 (bullseye)
msrcazl3_postgresql_16.4-2_on_azure_linux_3.0
msrcazl3_postgresql_16.5-1_on_azure_linux_3.0
msrccbl2_postgresql_14.13-1_on_cbl_mariner_2.0
msrccbl2_postgresql_14.14-1_on_cbl_mariner_2.0
postgresqlpostgresql>= 12.0 < 12.2112.21
postgresqlpostgresql>= 13.0 < 13.1713.17
postgresqlpostgresql>= 14.0 < 14.1414.14
postgresqlpostgresql>= 15.0 < 15.915.9
postgresqlpostgresql>= 16.0 < 16.516.5
postgresqlpostgresql>= 17.0 < 17.117.1

CVSS provenance

nvdv3.15.4MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N
osv7.5HIGH
vendor_debian7.5HIGH
vendor_redhat7.5HIGH
vendor_msrc5.4MEDIUM
vendor_ubuntu4.2MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.