CVE-2020-1720

A flaw was found in PostgreSQL's "ALTER ... DEPENDS ON EXTENSION", where sub-commands did not perform authorization checks. An authenticated attacker could use this flaw in certain configurations to perform drop objects such as function, triggers, et al., leading to database corruption. This issue affects PostgreSQL versions before 12.2, before 11.7, before 10.12 and before 9.6.17.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
3.1 LOW
NETWORK
HIGH
LOW
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:N
Base Score
CVSS 3.x
EPSS Score
Percentile: 57%
Affected Products (NVD)
VendorProductVersion
postgresqlpostgresql
9.6 ≤
𝑥
< 9.6.17
postgresqlpostgresql
10.0 ≤
𝑥
< 10.12
postgresqlpostgresql
11.0 ≤
𝑥
< 11.7
postgresqlpostgresql
12.0 ≤
𝑥
< 12.2
redhatdecision_manager
7.0
redhatsoftware_collections
-
redhatenterprise_linux
8.0
𝑥
= Vulnerable software versions
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
postgresql-10
bionic
Fixed 10.12-0ubuntu0.18.04.1
released
eoan
dne
trusty
dne
xenial
dne
postgresql-11
bionic
dne
eoan
Fixed 11.7-0ubuntu0.19.10.1
released
trusty
dne
xenial
dne
postgresql-12
bionic
dne
eoan
dne
trusty
dne
xenial
dne
postgresql-9.1
bionic
dne
eoan
dne
trusty
dne
xenial
dne
postgresql-9.3
bionic
dne
eoan
dne
trusty
not-affected
xenial
dne
postgresql-9.5
bionic
dne
eoan
dne
trusty
dne
xenial
not-affected
openSUSE logo
openSUSE / SLES Releases
openSUSE Product
Release
libecpg6
suse enterprise sap 12 SP1
10.12-1.18.1
fixed
suse enterprise sap 12 SP4
10.12-1.18.1
fixed
suse enterprise sap 12 SP5
10.12-1.18.1
fixed
suse enterprise sap 15
10.12-4.19.1
fixed
suse enterprise sap 15 SP1
12.3-3.8.1
fixed
suse enterprise sap 15 SP2
12.2-6.1
fixed
suse enterprise server 12 SP1
10.12-1.18.1
fixed
suse enterprise server 12 SP2
10.12-1.18.1
fixed
suse enterprise server 12 SP3
10.12-1.18.1
fixed
suse enterprise server 12 SP4
10.12-1.18.1
fixed
suse enterprise server 12 SP5
10.12-1.18.1
fixed
suse enterprise server 15
10.13-4.22.4
fixed
suse enterprise server 15 SP1
12.3-3.8.1
fixed
suse enterprise server 15 SP2
12.2-6.1
fixed
libpq5
suse enterprise desktop 15
10.12-4.19.1
fixed
suse enterprise desktop 15 SP1
12.3-3.8.1
fixed
suse enterprise desktop 15 SP2
12.2-6.1
fixed
suse enterprise sap 12 SP1
10.12-1.18.1
fixed
suse enterprise sap 12 SP4
10.12-1.18.1
fixed
suse enterprise sap 12 SP5
10.12-1.18.1
fixed
suse enterprise sap 15
10.12-4.19.1
fixed
suse enterprise sap 15 SP1
12.3-3.8.1
fixed
suse enterprise sap 15 SP2
12.2-6.1
fixed
suse enterprise server 12 SP1
10.12-1.18.1
fixed
suse enterprise server 12 SP2
10.12-1.18.1
fixed
suse enterprise server 12 SP3
10.12-1.18.1
fixed
suse enterprise server 12 SP4
10.12-1.18.1
fixed
suse enterprise server 12 SP5
10.12-1.18.1
fixed
suse enterprise server 15
10.13-4.22.4
fixed
suse enterprise server 15 SP1
12.3-3.8.1
fixed
suse enterprise server 15 SP2
12.2-6.1
fixed
libpq5-32bit
suse enterprise desktop 15 SP1
12.3-3.8.1
fixed
suse enterprise sap 12 SP1
10.12-1.18.1
fixed
suse enterprise sap 12 SP4
10.12-1.18.1
fixed
suse enterprise sap 12 SP5
10.12-1.18.1
fixed
suse enterprise sap 15 SP1
12.3-3.8.1
fixed
suse enterprise server 12 SP1
10.12-1.18.1
fixed
suse enterprise server 12 SP2
10.12-1.18.1
fixed
suse enterprise server 12 SP3
10.12-1.18.1
fixed
suse enterprise server 12 SP4
10.12-1.18.1
fixed
suse enterprise server 12 SP5
10.12-1.18.1
fixed
suse enterprise server 15
10.13-4.22.4
fixed
suse enterprise server 15 SP1
12.3-3.8.1
fixed
postgresql
suse enterprise desktop 15 SP1
12.0.1-8.14.1
fixed
suse enterprise sap 15 SP1
12.0.1-8.14.1
fixed
suse enterprise server 15
12.0.1-8.14.1
fixed
suse enterprise server 15 SP1
12.0.1-8.14.1
fixed
postgresql-contrib
suse enterprise sap 15 SP1
12.0.1-8.14.1
fixed
suse enterprise server 15
12.0.1-8.14.1
fixed
suse enterprise server 15 SP1
12.0.1-8.14.1
fixed
postgresql-devel
suse enterprise sap 15 SP1
12.0.1-8.14.1
fixed
suse enterprise server 15
12.0.1-8.14.1
fixed
suse enterprise server 15 SP1
12.0.1-8.14.1
fixed
postgresql-docs
suse enterprise sap 15 SP1
12.0.1-8.14.1
fixed
suse enterprise server 15
12.0.1-8.14.1
fixed
suse enterprise server 15 SP1
12.0.1-8.14.1
fixed
postgresql-plperl
suse enterprise sap 15 SP1
12.0.1-8.14.1
fixed
suse enterprise server 15
12.0.1-8.14.1
fixed
suse enterprise server 15 SP1
12.0.1-8.14.1
fixed
postgresql-plpython
suse enterprise sap 15 SP1
12.0.1-8.14.1
fixed
suse enterprise server 15
12.0.1-8.14.1
fixed
suse enterprise server 15 SP1
12.0.1-8.14.1
fixed
postgresql-pltcl
suse enterprise sap 15 SP1
12.0.1-8.14.1
fixed
suse enterprise server 15
12.0.1-8.14.1
fixed
suse enterprise server 15 SP1
12.0.1-8.14.1
fixed
postgresql-server
suse enterprise sap 15 SP1
12.0.1-8.14.1
fixed
suse enterprise server 15
12.0.1-8.14.1
fixed
suse enterprise server 15 SP1
12.0.1-8.14.1
fixed
postgresql-server-devel
suse enterprise sap 15 SP1
12.0.1-8.14.1
fixed
suse enterprise server 15 SP1
12.0.1-8.14.1
fixed
postgresql10
suse enterprise desktop 15
10.12-4.19.1
fixed
suse enterprise desktop 15 SP1
10.12-8.13.10
fixed
suse enterprise desktop 15 SP2
10.12-8.9.1
fixed
suse enterprise sap 12 SP1
10.12-1.18.1
fixed
suse enterprise sap 12 SP4
10.12-1.18.1
fixed
suse enterprise sap 12 SP5
10.12-1.18.1
fixed
suse enterprise sap 15
10.12-4.19.1
fixed
suse enterprise sap 15 SP1
10.12-8.13.10
fixed
suse enterprise sap 15 SP2
10.12-8.9.1
fixed
suse enterprise sap 15 SP3
10.13-4.22.4
fixed
suse enterprise server 12 SP1
10.12-1.18.1
fixed
suse enterprise server 12 SP2
10.12-1.18.1
fixed
suse enterprise server 12 SP3
10.12-1.18.1
fixed
suse enterprise server 12 SP4
10.12-1.18.1
fixed
suse enterprise server 12 SP5
10.12-1.18.1
fixed
suse enterprise server 15
10.13-4.22.4
fixed
suse enterprise server 15 SP1
10.12-8.13.10
fixed
suse enterprise server 15 SP2
10.12-8.9.1
fixed
suse enterprise server 15 SP3
10.13-4.22.4
fixed
postgresql10-contrib
suse enterprise sap 12 SP1
10.12-1.18.1
fixed
suse enterprise sap 12 SP4
10.12-1.18.1
fixed
suse enterprise sap 12 SP5
10.12-1.18.1
fixed
suse enterprise sap 15
10.12-4.19.1
fixed
suse enterprise sap 15 SP1
10.12-8.13.10
fixed
suse enterprise sap 15 SP2
10.12-8.9.1
fixed
suse enterprise sap 15 SP3
10.13-4.22.4
fixed
suse enterprise server 12 SP1
10.12-1.18.1
fixed
suse enterprise server 12 SP2
10.12-1.18.1
fixed
suse enterprise server 12 SP3
10.12-1.18.1
fixed
suse enterprise server 12 SP4
10.12-1.18.1
fixed
suse enterprise server 12 SP5
10.12-1.18.1
fixed
suse enterprise server 15
10.13-4.22.4
fixed
suse enterprise server 15 SP1
10.12-8.13.10
fixed
suse enterprise server 15 SP2
10.12-8.9.1
fixed
suse enterprise server 15 SP3
10.13-4.22.4
fixed
postgresql10-devel
suse enterprise sap 15
10.12-4.19.1
fixed
suse enterprise sap 15 SP1
10.12-8.13.9
fixed
suse enterprise sap 15 SP2
10.12-8.9.1
fixed
suse enterprise sap 15 SP3
10.13-4.22.4
fixed
suse enterprise server 15
10.13-4.22.4
fixed
suse enterprise server 15 SP1
10.12-8.13.9
fixed
suse enterprise server 15 SP2
10.12-8.9.1
fixed
suse enterprise server 15 SP3
10.13-4.22.4
fixed
postgresql10-docs
suse enterprise sap 12 SP1
10.12-1.18.1
fixed
suse enterprise sap 12 SP4
10.12-1.18.1
fixed
suse enterprise sap 12 SP5
10.12-1.18.1
fixed
suse enterprise sap 15
10.12-4.19.1
fixed
suse enterprise sap 15 SP1
10.12-8.13.10
fixed
suse enterprise sap 15 SP2
10.12-8.9.1
fixed
suse enterprise server 12 SP1
10.12-1.18.1
fixed
suse enterprise server 12 SP2
10.12-1.18.1
fixed
suse enterprise server 12 SP3
10.12-1.18.1
fixed
suse enterprise server 12 SP4
10.12-1.18.1
fixed
suse enterprise server 12 SP5
10.12-1.18.1
fixed
suse enterprise server 15
10.13-4.22.4
fixed
suse enterprise server 15 SP1
10.12-8.13.10
fixed
suse enterprise server 15 SP2
10.12-8.9.1
fixed
postgresql10-plperl
suse enterprise sap 12 SP1
10.12-1.18.1
fixed
suse enterprise sap 12 SP4
10.12-1.18.1
fixed
suse enterprise sap 12 SP5
10.12-1.18.1
fixed
suse enterprise sap 15
10.12-4.19.1
fixed
suse enterprise sap 15 SP1
10.12-8.13.10
fixed
suse enterprise sap 15 SP2
10.12-8.9.1
fixed
suse enterprise sap 15 SP3
10.13-4.22.4
fixed
suse enterprise server 12 SP1
10.12-1.18.1
fixed
suse enterprise server 12 SP2
10.12-1.18.1
fixed
suse enterprise server 12 SP3
10.12-1.18.1
fixed
suse enterprise server 12 SP4
10.12-1.18.1
fixed
suse enterprise server 12 SP5
10.12-1.18.1
fixed
suse enterprise server 15
10.13-4.22.4
fixed
suse enterprise server 15 SP1
10.12-8.13.10
fixed
suse enterprise server 15 SP2
10.12-8.9.1
fixed
suse enterprise server 15 SP3
10.13-4.22.4
fixed
postgresql10-plpython
suse enterprise sap 12 SP1
10.12-1.18.1
fixed
suse enterprise sap 12 SP4
10.12-1.18.1
fixed
suse enterprise sap 12 SP5
10.12-1.18.1
fixed
suse enterprise sap 15
10.12-4.19.1
fixed
suse enterprise sap 15 SP1
10.12-8.13.10
fixed
suse enterprise sap 15 SP2
10.12-8.9.1
fixed
suse enterprise sap 15 SP3
10.13-4.22.4
fixed
suse enterprise server 12 SP1
10.12-1.18.1
fixed
suse enterprise server 12 SP2
10.12-1.18.1
fixed
suse enterprise server 12 SP3
10.12-1.18.1
fixed
suse enterprise server 12 SP4
10.12-1.18.1
fixed
suse enterprise server 12 SP5
10.12-1.18.1
fixed
suse enterprise server 15
10.13-4.22.4
fixed
suse enterprise server 15 SP1
10.12-8.13.10
fixed
suse enterprise server 15 SP2
10.12-8.9.1
fixed
suse enterprise server 15 SP3
10.13-4.22.4
fixed
postgresql10-pltcl
suse enterprise sap 12 SP1
10.12-1.18.1
fixed
suse enterprise sap 12 SP4
10.12-1.18.1
fixed
suse enterprise sap 12 SP5
10.12-1.18.1
fixed
suse enterprise sap 15
10.12-4.19.1
fixed
suse enterprise sap 15 SP1
10.12-8.13.10
fixed
suse enterprise sap 15 SP2
10.12-8.9.1
fixed
suse enterprise sap 15 SP3
10.13-4.22.4
fixed
suse enterprise server 12 SP1
10.12-1.18.1
fixed
suse enterprise server 12 SP2
10.12-1.18.1
fixed
suse enterprise server 12 SP3
10.12-1.18.1
fixed
suse enterprise server 12 SP4
10.12-1.18.1
fixed
suse enterprise server 12 SP5
10.12-1.18.1
fixed
suse enterprise server 15
10.13-4.22.4
fixed
suse enterprise server 15 SP1
10.12-8.13.10
fixed
suse enterprise server 15 SP2
10.12-8.9.1
fixed
suse enterprise server 15 SP3
10.13-4.22.4
fixed
postgresql10-server
suse enterprise sap 12 SP1
10.12-1.18.1
fixed
suse enterprise sap 12 SP4
10.12-1.18.1
fixed
suse enterprise sap 12 SP5
10.12-1.18.1
fixed
suse enterprise sap 15
10.12-4.19.1
fixed
suse enterprise sap 15 SP1
10.12-8.13.10
fixed
suse enterprise sap 15 SP2
10.12-8.9.1
fixed
suse enterprise sap 15 SP3
10.13-4.22.4
fixed
suse enterprise server 12 SP1
10.12-1.18.1
fixed
suse enterprise server 12 SP2
10.12-1.18.1
fixed
suse enterprise server 12 SP3
10.12-1.18.1
fixed
suse enterprise server 12 SP4
10.12-1.18.1
fixed
suse enterprise server 12 SP5
10.12-1.18.1
fixed
suse enterprise server 15
10.13-4.22.4
fixed
suse enterprise server 15 SP1
10.12-8.13.10
fixed
suse enterprise server 15 SP2
10.12-8.9.1
fixed
suse enterprise server 15 SP3
10.13-4.22.4
fixed
postgresql12
suse enterprise desktop 15 SP1
12.3-3.8.1
fixed
suse enterprise desktop 15 SP2
12.2-6.1
fixed
suse enterprise sap 15 SP1
12.3-3.8.1
fixed
suse enterprise sap 15 SP2
12.2-6.1
fixed
suse enterprise sap 15 SP3
12.6-8.16.1
fixed
suse enterprise server 15 SP1
12.3-3.8.1
fixed
suse enterprise server 15 SP2
12.2-6.1
fixed
suse enterprise server 15 SP3
12.6-8.16.1
fixed
postgresql12-contrib
suse enterprise sap 15 SP1
12.3-3.8.1
fixed
suse enterprise sap 15 SP2
12.2-6.1
fixed
suse enterprise sap 15 SP3
12.6-8.16.1
fixed
suse enterprise server 15 SP1
12.3-3.8.1
fixed
suse enterprise server 15 SP2
12.2-6.1
fixed
suse enterprise server 15 SP3
12.6-8.16.1
fixed
postgresql12-devel
suse enterprise sap 15 SP1
12.3-3.8.1
fixed
suse enterprise sap 15 SP2
12.2-6.1
fixed
suse enterprise sap 15 SP3
12.6-8.16.1
fixed
suse enterprise server 15 SP1
12.3-3.8.1
fixed
suse enterprise server 15 SP2
12.2-6.1
fixed
suse enterprise server 15 SP3
12.6-8.16.1
fixed
postgresql12-docs
suse enterprise sap 15 SP1
12.3-3.8.1
fixed
suse enterprise sap 15 SP2
12.2-6.1
fixed
suse enterprise sap 15 SP3
12.6-8.16.1
fixed
suse enterprise server 15 SP1
12.3-3.8.1
fixed
suse enterprise server 15 SP2
12.2-6.1
fixed
suse enterprise server 15 SP3
12.6-8.16.1
fixed
postgresql12-plperl
suse enterprise sap 15 SP1
12.3-3.8.1
fixed
suse enterprise sap 15 SP2
12.2-6.1
fixed
suse enterprise sap 15 SP3
12.6-8.16.1
fixed
suse enterprise server 15 SP1
12.3-3.8.1
fixed
suse enterprise server 15 SP2
12.2-6.1
fixed
suse enterprise server 15 SP3
12.6-8.16.1
fixed
postgresql12-plpython
suse enterprise sap 15 SP1
12.3-3.8.1
fixed
suse enterprise sap 15 SP2
12.2-6.1
fixed
suse enterprise sap 15 SP3
12.6-8.16.1
fixed
suse enterprise server 15 SP1
12.3-3.8.1
fixed
suse enterprise server 15 SP2
12.2-6.1
fixed
suse enterprise server 15 SP3
12.6-8.16.1
fixed
postgresql12-pltcl
suse enterprise sap 15 SP1
12.3-3.8.1
fixed
suse enterprise sap 15 SP2
12.2-6.1
fixed
suse enterprise sap 15 SP3
12.6-8.16.1
fixed
suse enterprise server 15 SP1
12.3-3.8.1
fixed
suse enterprise server 15 SP2
12.2-6.1
fixed
suse enterprise server 15 SP3
12.6-8.16.1
fixed
postgresql12-server
suse enterprise sap 15 SP1
12.3-3.8.1
fixed
suse enterprise sap 15 SP2
12.2-6.1
fixed
suse enterprise sap 15 SP3
12.6-8.16.1
fixed
suse enterprise server 15 SP1
12.3-3.8.1
fixed
suse enterprise server 15 SP2
12.2-6.1
fixed
suse enterprise server 15 SP3
12.6-8.16.1
fixed
postgresql12-server-devel
suse enterprise sap 15 SP1
12.3-3.8.1
fixed
suse enterprise sap 15 SP2
12.2-6.1
fixed
suse enterprise sap 15 SP3
12.6-8.16.1
fixed
suse enterprise server 15 SP1
12.3-3.8.1
fixed
suse enterprise server 15 SP2
12.2-6.1
fixed
suse enterprise server 15 SP3
12.6-8.16.1
fixed
postgresql96
suse enterprise sap 12 SP1
9.6.17-3.33.1
fixed
suse enterprise server 12 SP1
9.6.17-3.33.1
fixed
suse enterprise server 12 SP2
9.6.17-3.33.1
fixed
suse enterprise server 12 SP3
9.6.17-3.33.1
fixed
postgresql96-contrib
suse enterprise sap 12 SP1
9.6.17-3.33.1
fixed
suse enterprise server 12 SP1
9.6.17-3.33.1
fixed
suse enterprise server 12 SP2
9.6.17-3.33.1
fixed
suse enterprise server 12 SP3
9.6.17-3.33.1
fixed
postgresql96-docs
suse enterprise sap 12 SP1
9.6.17-3.33.1
fixed
suse enterprise server 12 SP1
9.6.17-3.33.1
fixed
suse enterprise server 12 SP2
9.6.17-3.33.1
fixed
suse enterprise server 12 SP3
9.6.17-3.33.1
fixed
postgresql96-plperl
suse enterprise sap 12 SP1
9.6.17-3.33.1
fixed
suse enterprise server 12 SP1
9.6.17-3.33.1
fixed
suse enterprise server 12 SP2
9.6.17-3.33.1
fixed
suse enterprise server 12 SP3
9.6.17-3.33.1
fixed
postgresql96-plpython
suse enterprise sap 12 SP1
9.6.17-3.33.1
fixed
suse enterprise server 12 SP1
9.6.17-3.33.1
fixed
suse enterprise server 12 SP2
9.6.17-3.33.1
fixed
suse enterprise server 12 SP3
9.6.17-3.33.1
fixed
postgresql96-pltcl
suse enterprise sap 12 SP1
9.6.17-3.33.1
fixed
suse enterprise server 12 SP1
9.6.17-3.33.1
fixed
suse enterprise server 12 SP2
9.6.17-3.33.1
fixed
suse enterprise server 12 SP3
9.6.17-3.33.1
fixed
postgresql96-server
suse enterprise sap 12 SP1
9.6.17-3.33.1
fixed
suse enterprise server 12 SP1
9.6.17-3.33.1
fixed
suse enterprise server 12 SP2
9.6.17-3.33.1
fixed
suse enterprise server 12 SP3
9.6.17-3.33.1
fixed
python3-psycopg2
suse enterprise desktop 15 SP1
2.8.4-5.4.6
fixed
suse enterprise desktop 15 SP2
2.8.4-5.4.6
fixed
suse enterprise sap 15 SP1
2.8.4-5.4.6
fixed
suse enterprise sap 15 SP2
2.8.4-5.4.6
fixed
suse enterprise server 15 SP1
2.8.4-5.4.6
fixed
suse enterprise server 15 SP2
2.8.4-5.4.6
fixed