INSERT ... ON CONFLICT DO UPDATE commands in PostgreSQL 10.x...
Vulnerability Description
INSERT ... ON CONFLICT DO UPDATE commands in PostgreSQL 10.x before 10.1, 9.6.x before 9.6.6, and 9.5.x before 9.5.10 disclose table contents that the invoker lacks privilege to read. These exploits affect only tables where the attacker lacks full read access but has both INSERT and UPDATE privileges. Exploits bypass row level security policies and lack of SELECT privilege.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2017-15099
Credits & Attribution
No credits recorded in the NVD database.
References
- http://www.securityfocus.com/bid/101781
- https://access.redhat.com/errata/RHSA-2018:2511
- https://www.postgresql.org/support/security/
- http://www.securitytracker.com/id/1039752
- https://www.postgresql.org/about/news/1801/
- https://access.redhat.com/errata/RHSA-2018:2566
- https://www.debian.org/security/2017/dsa-4028
More from Red Hat, Inc.
View All →Affected Vendor
Red Hat, Inc.
View all reports →