Vulnerabilidades en The PostgreSQL Global Development Group
6 resultadosAnálisis Vexday
PostgreSQL apresenta 6 vulnerabilidades catalogadas na base Vexday, nenhuma em exploração ativa ou com severidade crítica, indicando um postura de segurança estável. A fraqueza predominante é validação inadequada de entrada (CWE-20), padrão comum em aplicações complexas, mas sem atividade de exploit recente que demande ação imediata.
CVE-2018-1058—A flaw was found in the way Postgresql allowed a user to modify the behavior of a query for other users. An attacker with a user account couEPSS 13.2%CVE-2017-7486—PostgreSQL versions 8.4 - 9.6 are vulnerable to information leak in pg_user_mappings view which discloses foreign server passwords to any usEPSS 6.3%CVE-2017-7484—It was found that some selectivity estimation functions in PostgreSQL before 9.2.21, 9.3.x before 9.3.17, 9.4.x before 9.4.12, 9.5.x before EPSS 2.6%CVE-2017-7485—In PostgreSQL 9.3.x before 9.3.17, 9.4.x before 9.4.12, 9.5.x before 9.5.7, and 9.6.x before 9.6.3, it was found that the PGREQUIRESSL envirEPSS 2.0%CVE-2018-1052—Memory disclosure vulnerability in table partitioning was found in postgresql 10.x before 10.2, allowing an authenticated attacker to read aEPSS 1.8%CVE-2018-1053—In postgresql 9.3.x before 9.3.21, 9.4.x before 9.4.16, 9.5.x before 9.5.11, 9.6.x before 9.6.7 and 10.x before 10.2, pg_upgrade creates filEPSS 0.5%