↑↓ select↵ open⌫ change scopeOpen full search

PG.CENTER connects PostgreSQL documentation, reference, and ecosystem knowledge. Maintained by Pigsty.

CVE-2019-10130

PostgreSQL maintains statistics for tables by sampling data available in columns; this data is consulted during the query planning process. Prior to this release, a user able to execute SQL queries with permissions to read a given column could craft a leaky operator that could read whatever data had been sampled from that column. If this happened to include values from rows that the user is forbidden to see by a row security policy, the user could effectively bypass the policy. This is fixed by only allowing a non-leakproof operator to use this data if there are no relevant row security policies for the table. The PostgreSQL project thanks Dean Rasheed for reporting this problem.

Version Information

Affected branchIntroducedFixed InFix Published
10—10.82019-05-09
11—11.32019-05-09
9.5—9.5.172019-05-09
9.6—9.6.132019-05-09

CVSS 3.0

Overall Score3.1
Componentcore server
VectorAV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N

First published: 2019-05-09

Original security advisory · JSON · All advisories