INFSA-2024:10788: postgresql:16 security update
Information about definition
Identificator: INFSA-2024:10788
Type: security
Release date: 2025-07-14 20:32:13 UTC
Information about package
PostgreSQL is an advanced object-relational database management system (DBMS).
Vulnerabilities description
- CVE-2024-10976
A flaw was found in PostgreSQL. This vulnerability allows incorrect row-level security policies to be applied via subqueries, WITH queries, security invoker views, or SQL-language functions that reference tables with row-level security policies. This issue arises when a query is planned under one role and executed under another, potentially leading to unauthorized reads or modifications of data.
- CVE-2024-10978
A flaw was found in PostgreSQL. This vulnerability allows a less-privileged application user to view or change unintended rows using SET ROLE, SET SESSION AUTHORIZATION, or equivalent features resulting in loss of confidentiality integrity and availability.
- CVE-2024-10979
A flaw was found in PostgreSQL PL/Perl. This vulnerability allows an unprivileged database user to change sensitive process environment variables (e.g., PATH) via incorrect control of environment variables.
Severity level
CVE | Score CVSS 2.0 | Score CVSS 3.x | Score CVSS 4.0 |
---|---|---|---|
NIST — CVE-2024-10976
|
no information | 4.2 | no information |
NIST — CVE-2024-10978
|
no information | 4.2 | no information |
NIST — CVE-2024-10979
|
no information | 8.8 | no information |
Updated packages