CVE-2024-4317

Missing authorization in PostgreSQL built-in views pg_stats_ext and pg_stats_ext_exprs allows an unprivileged database user to read most common values and other statistics from CREATE STATISTICS commands of other users. The most common values may reveal column values the eavesdropper could not otherwise read or results of functions they cannot execute. Installing an unaffected version only fixes fresh PostgreSQL installations, namely those that are created with the initdb utility after installing that version. Current PostgreSQL installations will remain vulnerable until they follow the instructions in the release notes. Within major versions 14-16, minor versions before PostgreSQL 16.3, 15.7, and 14.12 are affected. Versions before PostgreSQL 14 are unaffected.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
3.1 LOW
NETWORK
HIGH
LOW
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N
PostgreSQLCNA
3.1 LOW
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N
CISA-ADPADP
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 4%
VendorProductVersion
postgresqlpostgresql
14.0 ≤
𝑥
< 14.12
postgresqlpostgresql
15.0 ≤
𝑥
< 15.7
postgresqlpostgresql
16.0 ≤
𝑥
< 16.3
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
postgresql-13
bullseye
13.16-0+deb11u1
fixed
bullseye (security)
13.21-0+deb11u1
fixed
postgresql-15
bookworm
15.13-0+deb12u1
fixed
bookworm (security)
15.10-0+deb12u1
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
postgresql-10
noble
dne
mantic
dne
jammy
dne
focal
dne
bionic
not-affected
postgresql-12
noble
dne
mantic
dne
jammy
dne
focal
not-affected
postgresql-14
noble
dne
mantic
dne
jammy
Fixed 14.12-0ubuntu0.22.04.1
released
focal
dne
postgresql-15
noble
dne
mantic
Fixed 15.7-0ubuntu0.23.10.1
released
jammy
dne
focal
dne
postgresql-16
noble
Fixed 16.3-0ubuntu0.24.04.1
released
mantic
dne
jammy
dne
focal
dne
postgresql-9.1
noble
dne
mantic
dne
jammy
dne
focal
dne
postgresql-9.3
noble
dne
mantic
dne
jammy
dne
focal
dne
trusty
not-affected
postgresql-9.5
noble
dne
mantic
dne
jammy
dne
focal
dne
xenial
not-affected