Back

MEDIUM

postgresql: INSERT ... ON CONFLICT DO UPDATE fails to enforce SELECT privileges

Published Nov 22, 2017

Description

INSERT ... ON CONFLICT DO UPDATE commands in PostgreSQL 10.x before 10.1, 9.6.x before 9.6.6, and 9.5.x before 9.5.10 disclose table contents that the invoker lacks privilege to read. These exploits affect only tables where the attacker lacks full read access but has both INSERT and UPDATE privileges. Exploits bypass row level security policies and lack of SELECT privilege.

Affected products

Remediation

Red Hat statement

This issue affects the versions of rh-postgresql95-postgresql, and rh-postgresql96-postgresql as shipped with Red Hat Software Collections 3. Red Hat Product Security has rated this issue as having Low security impact. A future update may address this issue. For additional information, refer to the Issue Severity Classification: https://access.redhat.com/security/updates/classification/.

Metrics

References (11)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner redhat
Published Nov 22, 2017
Updated Sep 16, 2024
Reserved Oct 8, 2017
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Low
Public date Nov 9, 2017