CVE-2019-10130
low-risk
Published 2019-07-30
A vulnerability was found in PostgreSQL versions 11.x up to excluding 11.3, 10.x up to excluding 10.8, 9.6.x up to, excluding 9.6.13, 9.5.x up to, excluding 9.5.17. PostgreSQL maintains column statistics for tables. Certain statistics, such as histograms and lists of most common values, contain values taken from the column. PostgreSQL does not evaluate row security policies before consulting those statistics during query planning; an attacker can exploit this to read the most common values of certain columns. Affected columns are those for which the attacker has SELECT privilege and for which, in an ordinary query, row-level security prunes the set of rows visible to the attacker.
Do I need to act?
-
0.20% chance of exploitation
EPSS score — low exploit probability
-
Not on CISA KEV list
No confirmed active exploitation reported to CISA
?
Patch status unknown
Check vendor advisories for fix availability and mitigation guidance
4
CVSS 4.3/10
Medium
NETWORK
/ LOW complexity
Affected Products (2)
Affected Vendors
References (8)
Issue Tracking
https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-10130
Third Party Advisory
https://security.gentoo.org/glsa/202003-03
Vendor Advisory
https://www.postgresql.org/about/news/1939/
Issue Tracking
https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-10130
Third Party Advisory
https://security.gentoo.org/glsa/202003-03
Vendor Advisory
https://www.postgresql.org/about/news/1939/
26
/ 100
low-risk
Severity
18/34 · Moderate
Exploitability
1/34 · Minimal
Exposure
7/34 · Low