CVE-2017-15099

Source
https://nvd.nist.gov/vuln/detail/CVE-2017-15099
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2017-15099.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2017-15099
Downstream
Related
Published
2017-11-22T18:29:00Z
Modified
2025-04-20T01:37:25Z
Severity
  • 6.5 (Medium) CVSS_V3 - CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N CVSS Calculator
Summary
[none]
Details

INSERT ... ON CONFLICT DO UPDATE commands in PostgreSQL 10.x before 10.1, 9.6.x before 9.6.6, and 9.5.x before 9.5.10 disclose table contents that the invoker lacks privilege to read. These exploits affect only tables where the attacker lacks full read access but has both INSERT and UPDATE privileges. Exploits bypass row level security policies and lack of SELECT privilege.

References

Affected packages