PT-2020-5316 · Postgresql+7 · Postgresql+7

Tom Lane

·

Published

2019-08-07

·

Updated

2024-06-15

·

CVE-2020-1720

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions PostgreSQL versions prior to 12.2 PostgreSQL versions prior to 11.7 PostgreSQL versions prior to 10.12 PostgreSQL versions prior to 9.6.17
Description A flaw was found in PostgreSQL's "ALTER ... DEPENDS ON EXTENSION", where sub-commands did not perform authorization checks. An authenticated attacker could use this flaw in certain configurations to perform drop objects such as function, triggers, et al., leading to database corruption.
Recommendations For versions prior to 12.2, update to version 12.2 or later. For versions prior to 11.7, update to version 11.7 or later. For versions prior to 10.12, update to version 10.12 or later. For versions prior to 9.6.17, update to version 9.6.17 or later.

Fix

Improper Authorization

Missing Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2020:5620
ALT-PU-2020-1177
ALT-PU-2020-1178
ALT-PU-2020-1179
ALT-PU-2020-1180
ALT-PU-2020-1181
ALT-PU-2020-1257
ALT-PU-2020-1258
ALT-PU-2020-1259
ALT-PU-2020-1260
ALT-PU-2020-1261
BDU:2021-00082
BIT-POSTGRESQL-2020-1720
CESA-2020_3669
CESA-2020_5619
CESA-2020_5620
CVE-2020-1720
DLA-2105-1
DSA-4622-1
DSA-4623-1
MGASA-2020-0095
OPENSUSE-SU-2020:0331-1
OPENSUSE-SU-2020:1227-1
OPENSUSE-SU-2020_0331-1
OPENSUSE-SU-2020_1227-1
OPENSUSE-SU-2024:11184-1
OPENSUSE-SU-2024:11185-1
OPENSUSE-SU-2024:11186-1
RHSA-2020:0980
RHSA-2020:3669
RHSA-2020:4295
RHSA-2020:5112
RHSA-2020:5619
RHSA-2020:5620
RHSA-2020:5661
RHSA-2020:5664
RHSA-2020_3669
RHSA-2020_5619
RHSA-2020_5620
RHSA-2021:0163
RHSA-2021:0164
RHSA-2021:0166
RHSA-2021:0167
RLSA-2020:5620
SUSE-RU-2020:1280-1
SUSE-SU-2020:0586-1
SUSE-SU-2020:0589-1
SUSE-SU-2020:0715-1
SUSE-SU-2020:0752-1
SUSE-SU-2020:2149-1
SUSE-SU-2020_0586-1
SUSE-SU-2020_0589-1
SUSE-SU-2020_0715-1
SUSE-SU-2020_0752-1
SUSE-SU-2020_2149-1
USN-4282-1

Affected Products

Alt Linux
Almalinux
Centos
Postgresql
Red Hat
Rocky Linux
Suse
Ubuntu