CVE-2024-4317
published 2024-05-14CVE-2024-4317: Missing authorization in PostgreSQL built-in views pg_stats_ext and pg_stats_ext_exprs allows an unprivileged database user to read most common values and…
PriorityP423medium4.3CVSS 3.1
AVNACLPRLUINSUCLINAN
EPSS
0.72%
49.8th percentile
Missing authorization in PostgreSQL built-in views pg_stats_ext and pg_stats_ext_exprs allows an unprivileged database user to read most common values and other statistics from CREATE STATISTICS commands of other users. The most common values may reveal column values the eavesdropper could not otherwise read or results of functions they cannot execute. Installing an unaffected version only fixes fresh PostgreSQL installations, namely those that are created with the initdb utility after installing that version. Current PostgreSQL installations will remain vulnerable until they follow the instructions in the release notes. Within major versions 14-16, minor versions before PostgreSQL 16.3, 15.7, and 14.12 are affected. Versions before PostgreSQL 14 are unaffected.
Affected
11 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | postgresql-13 | < postgresql-15 15.7-0+deb12u1 (bookworm) | postgresql-15 15.7-0+deb12u1 (bookworm) |
| debian | postgresql-15 | < postgresql-15 15.7-0+deb12u1 (bookworm) | postgresql-15 15.7-0+deb12u1 (bookworm) |
| msrc | azl3_postgresql_16.1-1_on_azure_linux_3.0 | — | — |
| msrc | azl3_postgresql_16.3-1_on_azure_linux_3.0 | — | — |
| msrc | cbl2_postgresql_14.11-1_on_cbl_mariner_2.0 | — | — |
| postgresql | postgresql | >= 14 < 14.12 | 14.12 |
| postgresql | postgresql | >= 14.0 < 14.12 | 14.12 |
| postgresql | postgresql | >= 15 < 15.7 | 15.7 |
| postgresql | postgresql | >= 15.0 < 15.7 | 15.7 |
| postgresql | postgresql | >= 16 < 16.3 | 16.3 |
| postgresql | postgresql | >= 16.0 < 16.3 | 16.3 |
CVSS provenance
nvdv3.14.3MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
osv4.3MEDIUM
vendor_msrc4.3MEDIUM
vendor_debian3.1LOW
vendor_redhat3.1LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
PostgreSQL vulnerability
vendor_ubuntu·2024-05-30
CVE-2024-4317 PostgreSQL vulnerability
Title: PostgreSQL vulnerability
Summary: PostgreSQL could be made to expose sensitive information.
Lukas Fittl discovered that PostgreSQL incorrectly performed authorization
in the built-in pg_stats_ext and pg_stats_ext_exprs views. An unprivileged
database user can use this issue to read most common values and other
statistics from CREATE STATISTICS commands of other users.
NOTE: This update will only fix fresh PostgreSQL installations. Current
PostgreSQL installations will remain vulnerable to this issue until manual
steps are performed. Please see the instructions in the changelog located
at /usr/share/doc/postgresql-*/changelog.Debian.gz after the updated
packages have been installed, or in the PostgreSQL release notes located
here:
https://www.postgresql.org/docs/16/release-16-3.h
Microsoft
PostgreSQL pg_stats_ext and pg_stats_ext_exprs lack authorization checks
vendor_msrc·2024-05-14·CVSS 4.3
CVE-2024-4317 [LOW] CWE-862 PostgreSQL pg_stats_ext and pg_stats_ext_exprs lack authorization checks
PostgreSQL pg_stats_ext and pg_stats_ext_exprs lack authorization checks
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparency in this work which is why we began publishing CSAF/VEX in October 2025. See this blog post for more information. If impact to additional products is identified, we will update the CVE to reflect this.
Mariner: Mariner
PostgreSQL: PostgreSQL
Customer Action Required: Yes
Remediation: CBL-Mariner Release
Red Hat
postgresql: PostgreSQL pg_stats_ext and pg_stats_ext_exprs lack authorization checks
vendor_redhat·2024-05-09·CVSS 3.1
CVE-2024-4317 [LOW] CWE-862 postgresql: PostgreSQL pg_stats_ext and pg_stats_ext_exprs lack authorization checks
postgresql: PostgreSQL pg_stats_ext and pg_stats_ext_exprs lack authorization checks
Missing authorization in PostgreSQL built-in views pg_stats_ext and pg_stats_ext_exprs allows an unprivileged database user to read most common values and other statistics from CREATE STATISTICS commands of other users. The most common values may reveal column values the eavesdropper could not otherwise read or results of functions they cannot execute. Installing an unaffected version only fixes fresh PostgreSQL installations, namely those that are created with the initdb utility after installing that version. Current PostgreSQL installations will remain vulnerable until they follow the instructions in the release notes. Within major versions 14-16, minor versions before PostgreSQL 16.3, 15.7, and 14.12 a
Debian
CVE-2024-4317: postgresql-13 - Missing authorization in PostgreSQL built-in views pg_stats_ext and pg_stats_ext...
vendor_debian·2024·CVSS 3.1
CVE-2024-4317 [LOW] CVE-2024-4317: postgresql-13 - Missing authorization in PostgreSQL built-in views pg_stats_ext and pg_stats_ext...
Missing authorization in PostgreSQL built-in views pg_stats_ext and pg_stats_ext_exprs allows an unprivileged database user to read most common values and other statistics from CREATE STATISTICS commands of other users. The most common values may reveal column values the eavesdropper could not otherwise read or results of functions they cannot execute. Installing an unaffected version only fixes fresh PostgreSQL installations, namely those that are created with the initdb utility after installing that version. Current PostgreSQL installations will remain vulnerable until they follow the instructions in the release notes. Within major versions 14-16, minor versions before PostgreSQL 16.3, 15.7, and 14.12 are affected. Versions before PostgreSQL 14 are unaffected.
Scope: local
bullseye: reso
GHSA
GHSA-37xw-rpjg-xxfx: Missing authorization in PostgreSQL built-in views pg_stats_ext and pg_stats_ext_exprs allows an unprivileged database user to read most common values
ghsa_unreviewed·2024-05-14
CVE-2024-4317 [LOW] CWE-862 GHSA-37xw-rpjg-xxfx: Missing authorization in PostgreSQL built-in views pg_stats_ext and pg_stats_ext_exprs allows an unprivileged database user to read most common values
Missing authorization in PostgreSQL built-in views pg_stats_ext and pg_stats_ext_exprs allows an unprivileged database user to read most common values and other statistics from CREATE STATISTICS commands of other users. The most common values may reveal column values the eavesdropper could not otherwise read or results of functions they cannot execute. Installing an unaffected version only fixes fresh PostgreSQL installations, namely those that are created with the initdb utility after installing that version. Current PostgreSQL installations will remain vulnerable until they follow the instructions in the release notes. Within major versions 14-16, minor versions before PostgreSQL 16.3, 15.7, and 14.12 are affected. Versions before PostgreSQL 14 are unaffected.
OSV
CVE-2024-4317: Missing authorization in PostgreSQL built-in views pg_stats_ext and pg_stats_ext_exprs allows an unprivileged database user to read most common values
osv·2024-05-14·CVSS 4.3
CVE-2024-4317 [MEDIUM] CVE-2024-4317: Missing authorization in PostgreSQL built-in views pg_stats_ext and pg_stats_ext_exprs allows an unprivileged database user to read most common values
Missing authorization in PostgreSQL built-in views pg_stats_ext and pg_stats_ext_exprs allows an unprivileged database user to read most common values and other statistics from CREATE STATISTICS commands of other users. The most common values may reveal column values the eavesdropper could not otherwise read or results of functions they cannot execute. Installing an unaffected version only fixes fresh PostgreSQL installations, namely those that are created with the initdb utility after installing that version. Current PostgreSQL installations will remain vulnerable until they follow the instructions in the release notes. Within major versions 14-16, minor versions before PostgreSQL 16.3, 15.7, and 14.12 are affected. Versions before PostgreSQL 14 are unaffected.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2024-05-14
Published