A vulnerability was found in PostgreSQL with the use of the MERGE command, which fails to test new rows against row security policies defined for UPDATE and SELECT. If UPDATE and SELECT policies forbid some rows that INSERT policies do not forbid, a user could store such rows.
History

Mon, 16 Sep 2024 16:30:00 +0000


cve-icon MITRE

Status: PUBLISHED

Assigner: redhat

Published: 2023-08-11T12:19:15.819Z

Updated: 2024-09-16T15:50:50.495Z

Reserved: 2023-08-01T09:31:02.842Z

Link: CVE-2023-39418

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2023-08-11T13:15:09.963

Modified: 2024-09-16T16:15:04.650

Link: CVE-2023-39418

cve-icon Redhat

Severity : Low

Publid Date: 2023-08-10T00:00:00Z

Links: CVE-2023-39418 - Bugzilla