CVE-2024-4317

EUVD-2024-43960
Missing authorization in PostgreSQL built-in views pg_stats_ext and pg_stats_ext_exprs allows an unprivileged database user to read most common values and other statistics from CREATE STATISTICS commands of other users. The most common values may reveal column values the eavesdropper could not otherwise read or results of functions they cannot execute. Installing an unaffected version only fixes fresh PostgreSQL installations, namely those that are created with the initdb utility after installing that version. Current PostgreSQL installations will remain vulnerable until they follow the instructions in the release notes. Within major versions 14-16, minor versions before PostgreSQL 16.3, 15.7, and 14.12 are affected. Versions before PostgreSQL 14 are unaffected.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
3.1 LOW
NETWORK
HIGH
LOW
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N
PostgreSQLCNA
3.1 LOW
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N
Base Score
CVSS 3.x
EPSS Score
Percentile: 43%
Affected Products (NVD)
VendorProductVersion
postgresqlpostgresql
14.0 ≤
𝑥
< 14.12
postgresqlpostgresql
15.0 ≤
𝑥
< 15.7
postgresqlpostgresql
16.0 ≤
𝑥
< 16.3
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
postgresql-13
bullseye
13.16-0+deb11u1
fixed
bullseye (security)
13.23-0+deb11u1
fixed
postgresql-15
bookworm
15.14-0+deb12u1
fixed
bookworm (security)
15.10-0+deb12u1
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
postgresql-16
focal
dne
jammy
dne
mantic
dne
noble
Fixed 16.3-0ubuntu0.24.04.1
released
postgresql-15
focal
dne
jammy
dne
mantic
Fixed 15.7-0ubuntu0.23.10.1
released
noble
dne
postgresql-14
focal
dne
jammy
Fixed 14.12-0ubuntu0.22.04.1
released
mantic
dne
noble
dne
postgresql-12
focal
not-affected
jammy
dne
mantic
dne
noble
dne
postgresql-10
bionic
not-affected
focal
dne
jammy
dne
mantic
dne
noble
dne
postgresql-9.5
focal
dne
jammy
dne
mantic
dne
noble
dne
xenial
not-affected
postgresql-9.3
focal
dne
jammy
dne
mantic
dne
noble
dne
trusty
not-affected
postgresql-9.1
focal
dne
jammy
dne
mantic
dne
noble
dne