CVE-2023-39418

CVSS 3.1 Score 4.3 of 10 (medium)

Details

Published Aug 11, 2023
Updated: Feb 16, 2024

Summary

CVE-2023-39418 is a newly discovered vulnerability affecting PostgreSQL. The issue stems from a flaw in the MERGE command, which fails to enforce row security policies during updates. Specifically, if UPDATE and SELECT policies restrict certain rows, but INSERT policies do not, a user can bypass these restrictions and insert unauthorized data. This could potentially lead to security breaches and unintended data modifications. It is recommended that users of PostgreSQL apply the necessary patches or upgrades to mitigate this vulnerability.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share

Affected Products

  • Red Hat Enterprise Linux
  • PostgreSQL
  • Debian

Affected Vendors

  • Postgresql
  • Red Hat
  • Debian