postgresql: Selectivity estimators bypass row security policies
Published Jul 30, 2019
4.3
MEDIUMCVSS 3.1
EPSS 1.08%
Description
A vulnerability was found in PostgreSQL versions 11.x up to excluding 11.3, 10.x up to excluding 10.8, 9.6.x up to, excluding 9.6.13, 9.5.x up to, excluding 9.5.17. PostgreSQL maintains column statistics for tables. Certain statistics, such as histograms and lists of most common values, contain values taken from the column. PostgreSQL does not evaluate row security policies before consulting those statistics during query planning; an attacker can exploit this to read the most common values of certain columns. Affected columns are those for which the attacker has SELECT privilege and for which, in an ordinary query, row-level security prunes the set of rows visible to the attacker.
Affected products
-
- Version 10.x up to, excluding 10.8StatusaffectedConstraints-
- Version 11.x up to, excluding 11.3StatusaffectedConstraints-
- Version 9.5.x up to, excluding 9.5.17StatusaffectedConstraints-
- Version 9.6.x up to, excluding 9.6.13StatusaffectedConstraints-
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | |||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| PostgreSQL Project | PostgreSQL | n/a |
|
Configuration 1
- ≥ 9.5.0 · < 9.5.17
- ≥ 9.6.0 · < 9.6.13
- ≥ 10.0 · < 10.8
- ≥ 11.0 · < 11.3
No data.
Red Hat Enterprise Linux 8
postgresql:10-8020020200825115746.4cda2c84
Fixed · RHSA-2020:3669
Red Hat Enterprise Linux 8
postgresql:9.6-8030020201201133334.229f0a1c
Fixed · RHSA-2020:5619
Red Hat Enterprise Linux 8.0 Update Services for SAP Solutions
postgresql:10-8000020201214113918.f8e95b4e
Fixed · RHSA-2020:5664
Red Hat Enterprise Linux 8.0 Update Services for SAP Solutions
postgresql:9.6-8000020201214122017.f8e95b4e
Fixed · RHSA-2020:5661
Red Hat Enterprise Linux 8.1 Extended Update Support
postgresql:10-8010020201214112129.c27ad7f8
Fixed · RHSA-2021:0166
Red Hat Enterprise Linux 8.1 Extended Update Support
postgresql:9.6-8010020201214134447.c27ad7f8
Fixed · RHSA-2021:0167
Red Hat Enterprise Linux 8.2 Extended Update Support
postgresql:9.6-8020020201201133334.4cda2c84
Fixed · RHSA-2021:0164
Red Hat Software Collections for Red Hat Enterprise Linux 7
rh-postgresql10-postgresql-0:10.12-2.el7
Fixed · RHSA-2020:0980
Red Hat Software Collections for Red Hat Enterprise Linux 7
rh-postgresql96-postgresql-0:9.6.19-1.el7
Fixed · RHSA-2020:4295
Red Hat Software Collections for Red Hat Enterprise Linux 7.5 EUS
rh-postgresql10-postgresql-0:10.12-2.el7
Fixed · RHSA-2020:0980
Red Hat Software Collections for Red Hat Enterprise Linux 7.6 EUS
rh-postgresql10-postgresql-0:10.12-2.el7
Fixed · RHSA-2020:0980
Red Hat Software Collections for Red Hat Enterprise Linux 7.6 EUS
rh-postgresql96-postgresql-0:9.6.19-1.el7
Fixed · RHSA-2020:4295
Red Hat Software Collections for Red Hat Enterprise Linux 7.7 EUS
rh-postgresql10-postgresql-0:10.12-2.el7
Fixed · RHSA-2020:0980
Red Hat Software Collections for Red Hat Enterprise Linux 7.7 EUS
rh-postgresql96-postgresql-0:9.6.19-1.el7
Fixed · RHSA-2020:4295
CloudForms Management Engine 5
postgresql94
Not affected
CloudForms Management Engine 5
postgresql96
Not affected
Red Hat Ansible Tower 3
postgresql96-libs
Not affected
Red Hat Enterprise Linux 5
postgresql
Not affected
Red Hat Enterprise Linux 6
postgresql
Not affected
Red Hat Enterprise Linux 7
postgresql
Not affected
Red Hat Enterprise Linux 8
libpq
Not affected
Red Hat Satellite 5
rh-postgresql95-postgresql
Not affected
Red Hat Satellite 6
postgresql
Not affected
Red Hat Software Collections
rh-postgresql95-postgresql
Fix deferred
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 8 | postgresql:10-8020020200825115746.4cda2c84 | Fixed | RHSA-2020:3669 |
| Red Hat Enterprise Linux 8 | postgresql:9.6-8030020201201133334.229f0a1c | Fixed | RHSA-2020:5619 |
| Red Hat Enterprise Linux 8.0 Update Services for SAP Solutions | postgresql:10-8000020201214113918.f8e95b4e | Fixed | RHSA-2020:5664 |
| Red Hat Enterprise Linux 8.0 Update Services for SAP Solutions | postgresql:9.6-8000020201214122017.f8e95b4e | Fixed | RHSA-2020:5661 |
| Red Hat Enterprise Linux 8.1 Extended Update Support | postgresql:10-8010020201214112129.c27ad7f8 | Fixed | RHSA-2021:0166 |
| Red Hat Enterprise Linux 8.1 Extended Update Support | postgresql:9.6-8010020201214134447.c27ad7f8 | Fixed | RHSA-2021:0167 |
| Red Hat Enterprise Linux 8.2 Extended Update Support | postgresql:9.6-8020020201201133334.4cda2c84 | Fixed | RHSA-2021:0164 |
| Red Hat Software Collections for Red Hat Enterprise Linux 7 | rh-postgresql10-postgresql-0:10.12-2.el7 | Fixed | RHSA-2020:0980 |
| Red Hat Software Collections for Red Hat Enterprise Linux 7 | rh-postgresql96-postgresql-0:9.6.19-1.el7 | Fixed | RHSA-2020:4295 |
| Red Hat Software Collections for Red Hat Enterprise Linux 7.5 EUS | rh-postgresql10-postgresql-0:10.12-2.el7 | Fixed | RHSA-2020:0980 |
| Red Hat Software Collections for Red Hat Enterprise Linux 7.6 EUS | rh-postgresql10-postgresql-0:10.12-2.el7 | Fixed | RHSA-2020:0980 |
| Red Hat Software Collections for Red Hat Enterprise Linux 7.6 EUS | rh-postgresql96-postgresql-0:9.6.19-1.el7 | Fixed | RHSA-2020:4295 |
| Red Hat Software Collections for Red Hat Enterprise Linux 7.7 EUS | rh-postgresql10-postgresql-0:10.12-2.el7 | Fixed | RHSA-2020:0980 |
| Red Hat Software Collections for Red Hat Enterprise Linux 7.7 EUS | rh-postgresql96-postgresql-0:9.6.19-1.el7 | Fixed | RHSA-2020:4295 |
| CloudForms Management Engine 5 | postgresql94 | Not affected | n/a |
| CloudForms Management Engine 5 | postgresql96 | Not affected | n/a |
| Red Hat Ansible Tower 3 | postgresql96-libs | Not affected | n/a |
| Red Hat Enterprise Linux 5 | postgresql | Not affected | n/a |
| Red Hat Enterprise Linux 6 | postgresql | Not affected | n/a |
| Red Hat Enterprise Linux 7 | postgresql | Not affected | n/a |
| Red Hat Enterprise Linux 8 | libpq | Not affected | n/a |
| Red Hat Satellite 5 | rh-postgresql95-postgresql | Not affected | n/a |
| Red Hat Satellite 6 | postgresql | Not affected | n/a |
| Red Hat Software Collections | rh-postgresql95-postgresql | Fix deferred | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
This vulnerability requires row level security to be in use, and an attacker to be able to execute crafted queries against the target PostgreSQL database. Neither of these conditions is true in Red Hat Ansible Tower, Red Hat CloudForms or Red Hat Satellite.
Metrics
No CVSS v4.0 score for this CVE.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
CVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N
AV:N/AC:L/Au:S/C:P/I:N/A:N
This CVE is not in the KEV list.
No CISA SSVC assessment for this CVE yet.
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 1, 2026.
Score over time
2021–2026- EPSS v1
- EPSS v5
- EPSS v2
- EPSS v3
Percentile over time
- EPSS v1
- EPSS v5
- EPSS v2
- EPSS v3
Table of values (12 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 1, 2026 | 1.08% (0.01085) | 64.00th | v5 (v2026.06.15) |
| Sep 20, 2026 | 1.08% (0.01085) | 63.76th | v5 (v2026.06.15) |
| Jul 20, 2024 | 0.17% (0.00168) | 53.95th | v3 (v2023.03.01) |
| Jul 10, 2024 | 0.17% (0.00168) | 53.86th | v3 (v2023.03.01) |
| Mar 7, 2023 | 0.17% (0.00168) | 51.81th | v3 (v2023.03.01) |
| Mar 6, 2023 | 0.95% (0.00950) | 32.28th | v2 (v2022.01.01) |
| Apr 1, 2022 | 0.95% (0.00950) | 28.61th | v2 (v2022.01.01) |
| Feb 4, 2022 | 6.73% (0.06726) | 78.88th | v2 (v2022.01.01) |
| Feb 3, 2022 | 4.50% (0.04504) | 76.47th | v1 |
| Jan 6, 2022 | 4.50% (0.04504) | 76.26th | v1 |
| Jan 5, 2022 | 1.04% (0.01040) | 65.70th | v5 (v2026.06.15) |
| Apr 14, 2021 | 1.04% (0.01040) | 0.00th | v1 |
References (8)
- http://lists.opensuse.org/opensuse-security-announce/2020-08/msg00043.html vendor-advisoryx_refsource_SUSEMailing ListThird Party Advisory
- https://access.redhat.com/security/cve/CVE-2019-10130 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1707109 Issue Tracking
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-10130 x_refsource_CONFIRMIssue TrackingThird Party Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2019-10130
- https://security.gentoo.org/glsa/202003-03 vendor-advisoryx_refsource_GENTOOThird Party Advisory
- https://www.cve.org/CVERecord?id=CVE-2019-10130
- https://www.postgresql.org/about/news/1939/ x_refsource_MISCVendor Advisory
| Link | Providers | Tags |
|---|---|---|
| http://lists.opensuse.org/opensuse-security-announce/2020-08/msg00043.html | vendor-advisoryx_refsource_SUSEMailing ListThird Party Advisory | |
| https://access.redhat.com/security/cve/CVE-2019-10130 | Vendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=1707109 | Issue Tracking | |
| https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-10130 | x_refsource_CONFIRMIssue TrackingThird Party Advisory | |
| https://nvd.nist.gov/vuln/detail/CVE-2019-10130 | ||
| https://security.gentoo.org/glsa/202003-03 | vendor-advisoryx_refsource_GENTOOThird Party Advisory | |
| https://www.cve.org/CVERecord?id=CVE-2019-10130 | ||
| https://www.postgresql.org/about/news/1939/ | x_refsource_MISCVendor Advisory |
Change history (0)
No recorded changes yet.