INSERT ... ON CONFLICT DO UPDATE commands in PostgreSQL 10.x before 10.1, 9.6.x before 9.6.6, and 9.5.x before 9.5.10 disclose table contents that the invoker lacks privilege to read. These exploits affect only tables where the attacker lacks full read access but has both INSERT and UPDATE privileges. Exploits bypass row level security policies and lack of SELECT privilege.
Metrics
Affected Vendors & Products
Advisories
| Source | ID | Title |
|---|---|---|
Debian DSA |
DSA-4028-1 | postgresql-9.6 security update |
Ubuntu USN |
USN-3479-1 | PostgreSQL vulnerabilities |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
No history.
Status: PUBLISHED
Assigner: redhat
Published:
Updated: 2024-09-16T16:43:27.924Z
Reserved: 2017-10-08T00:00:00
Link: CVE-2017-15099
No data.
Status : Deferred
Published: 2017-11-22T18:29:00.583
Modified: 2025-04-20T01:37:25.860
Link: CVE-2017-15099
OpenCVE Enrichment
No data.
Debian DSA
Ubuntu USN