CVE Vulnerabilities

CVE-2021-32028

Published: Oct 11, 2021 | Modified: Jan 31, 2023
CVSS 3.x
6.5
MEDIUM
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
CVSS 2.x
4 MEDIUM
AV:N/AC:L/Au:S/C:P/I:N/A:N
RedHat/V2
RedHat/V3
Ubuntu

A flaw was found in postgresql. Using an INSERT … ON CONFLICT … DO UPDATE command on a purpose-crafted table, an authenticated database user could read arbitrary bytes of server memory. The highest threat from this vulnerability is to data confidentiality.

Affected Software

Name Vendor Start Version End Version
Postgresql Postgresql 9.6.0 (including) 9.6.22 (excluding)
Postgresql Postgresql 10.0 (including) 10.17 (excluding)
Postgresql Postgresql 11.0 (including) 11.12 (excluding)
Postgresql Postgresql 12.0 (including) 12.7 (excluding)
Postgresql Postgresql 13.0 (including) 13.3 (excluding)

References