IM
IronMonkey Threat Research

CVE-2021-32028 MEDIUM

Published: 2021-10-11 | Last Modified: 2024-11-21 | Status: Modified

Description

A flaw was found in postgresql. Using an INSERT ... ON CONFLICT ... DO UPDATE command on a purpose-crafted table, an authenticated database user could read arbitrary bytes of server memory. The highest threat from this vulnerability is to data confidentiality.

Additional Descriptions (1)

Se ha encontrado un fallo en postgresql. Usando un comando INSERT ... ON CONFLICT ... DO UPDATE en una tabla diseñada a tal efecto, un usuario autenticado de la base de datos podía leer bytes arbitrarios de la memoria del servidor. La mayor amenaza de esta vulnerabilidad es la confidencialidad de los datos

CVSS Metrics

Base Score: 6.5 (MEDIUM)

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

Attack VectorNETWORK
Attack ComplexityLOW
Privileges RequiredLOW
User InteractionNONE
ScopeUNCHANGED
Confidentiality ImpactHIGH
Integrity ImpactNONE
Availability ImpactNONE

Source: [email protected]

Type: Primary

Exploitability Score: 2.8

Impact Score: 3.6

Base Score: 4.0 (MEDIUM)

AV:N/AC:L/Au:S/C:P/I:N/A:N

Access VectorNETWORK
Access ComplexityLOW
AuthenticationSINGLE
Confidentiality ImpactPARTIAL
Integrity ImpactNONE
Availability ImpactNONE

Source: [email protected]

Type: Primary

Exploitability Score: 8.0

Impact Score: 2.9

Weaknesses

Source Type Description
[email protected] Secondary
en CWE-200
[email protected] Primary
en NVD-CWE-noinfo

Affected Products

Vendor Product Version Update Type
postgresql postgresql * <built-in method update of dict object at 0x72a9cc660540> Application
postgresql postgresql * <built-in method update of dict object at 0x72a9cc662000> Application
postgresql postgresql * <built-in method update of dict object at 0x72a9b0b3bf40> Application
postgresql postgresql * <built-in method update of dict object at 0x72a9cc6d8480> Application
postgresql postgresql * <built-in method update of dict object at 0x72a9cc660600> Application

Affected Configurations

Operator: OR

Vulnerable CPE
Yes cpe:2.3:a:postgresql:postgresql:*:*:*:*:*:*:*:*
Yes cpe:2.3:a:postgresql:postgresql:*:*:*:*:*:*:*:*
Yes cpe:2.3:a:postgresql:postgresql:*:*:*:*:*:*:*:*
Yes cpe:2.3:a:postgresql:postgresql:*:*:*:*:*:*:*:*
Yes cpe:2.3:a:postgresql:postgresql:*:*:*:*:*:*:*:*

References

Notification
Message here