CVE-2025-8713Exposure of Sensitive Information Through Metadata in Postgresql-13

Severity
3.1LOWNVD
OSV7.5
EPSS
0.0%
top 89.73%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedAug 14
Latest updateSep 8

Description

PostgreSQL optimizer statistics allow a user to read sampled data within a view that the user cannot access. Separately, statistics allow a user to read sampled data that a row security policy intended to hide. PostgreSQL maintains statistics for tables by sampling data available in columns; this data is consulted during the query planning process. Prior to this release, a user could craft a leaky operator that bypassed view access control lists (ACLs) and bypassed row security policies in parti

CVSS vector

CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:NExploitability: 1.6 | Impact: 1.4

Affected Packages5 packages

debiandebian/postgresql-13< postgresql-13 13.22-0+deb11u1 (bullseye)
debiandebian/postgresql-15< postgresql-13 13.22-0+deb11u1 (bullseye)
debiandebian/postgresql-17< postgresql-13 13.22-0+deb11u1 (bullseye)

🔴Vulnerability Details

3
OSV
postgresql-14, postgresql-16, postgresql-17 vulnerabilities2025-09-08
OSV
CVE-2025-8713: PostgreSQL optimizer statistics allow a user to read sampled data within a view that the user cannot access2025-08-14
GHSA
GHSA-cqj3-wjpm-fjvp: PostgreSQL optimizer statistics allow a user to read sampled data within a view that the user cannot access2025-08-14

📋Vendor Advisories

4
Ubuntu
PostgreSQL vulnerabilities2025-09-08
Red Hat
postgresql: PostgreSQL optimizer statistics can expose sampled data within a view, partition, or child table2025-08-14
Microsoft
PostgreSQL optimizer statistics can expose sampled data within a view, partition, or child table2025-08-12
Debian
CVE-2025-8713: postgresql-13 - PostgreSQL optimizer statistics allow a user to read sampled data within a view ...2025