{"id":"CVE-2019-10130","year":2019,"sequence":10130,"component":"core server","score":3.1,"cvss_version":"3.0","vector":"AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N","first_published":"2019-05-09","source_url":"https://www.postgresql.org/support/security/CVE-2019-10130/","facts":{"affected":{"10":"10","11":"11","9.5":"9.5","9.6":"9.6"},"component":"core server","cvss_version":"3.0","description_en":"PostgreSQL maintains statistics for tables by sampling data available in columns; this data is consulted during the query planning process. Prior to this release, a user able to execute SQL queries with permissions to read a given column could craft a leaky operator that could read whatever data had been sampled from that column. If this happened to include values from rows that the user is forbidden to see by a row security policy, the user could effectively bypass the policy. This is fixed by only allowing a non-leakproof operator to use this data if there are no relevant row security policies for the table.\n\nThe PostgreSQL project thanks Dean Rasheed for reporting this problem.","first_published":"2019-05-09","fixed":{"10":"10.8","11":"11.3","9.5":"9.5.17","9.6":"9.6.13"},"id":"CVE-2019-10130","introduced":{},"published":{"10":"2019-05-09","11":"2019-05-09","9.5":"2019-05-09","9.6":"2019-05-09"},"score":3.1,"title":"Selectivity estimators bypass row security policies","url":"https://www.postgresql.org/support/security/CVE-2019-10130/","vector":"AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N"},"reviewed_hash":"6a65a7884245936f6adaef8709d290d460e999dfce1ad78734fa7c9a324ed325","source_hash":"965b9e2323feab543f3cbeb74c418c3a5b43cbefc6594d2862ff0d24dcf8e6a2","text":{"locale":"en","title":"Selectivity estimators bypass row security policies","description":"PostgreSQL maintains statistics for tables by sampling data available in columns; this data is consulted during the query planning process. Prior to this release, a user able to execute SQL queries with permissions to read a given column could craft a leaky operator that could read whatever data had been sampled from that column. If this happened to include values from rows that the user is forbidden to see by a row security policy, the user could effectively bypass the policy. This is fixed by only allowing a non-leakproof operator to use this data if there are no relevant row security policies for the table.\n\nThe PostgreSQL project thanks Dean Rasheed for reporting this problem.","details":null,"format":"plain","provenance":{"fetched_at":"2026-09-26T10:56:06+00:00","path":"compare/security.json","root":"source-data","sha256":"6a65a7884245936f6adaef8709d290d460e999dfce1ad78734fa7c9a324ed325","source_archive_sha256":"8d8ad63581e1d27b3a0f995ded3feb81c265e38b2ac652eb22f022f52c2240ec","source_revision":"004bc292ee31c11f9a41ab007e9d8116bce29a71","source_url":"https://www.postgresql.org/support/security/"},"text_hash":"d72919b54ab9f9e6306fc6b655de96c9f3aee3003ee9af96e782eb06023dc4f3"},"locales":["en"],"fixes":[{"major":"10","fixed_version":"10.8","introduced":null,"published_date":"2019-05-09","facts":{"fixed":"10.8","introduced":null,"published":"2019-05-09"}},{"major":"11","fixed_version":"11.3","introduced":null,"published_date":"2019-05-09","facts":{"fixed":"11.3","introduced":null,"published":"2019-05-09"}},{"major":"9.5","fixed_version":"9.5.17","introduced":null,"published_date":"2019-05-09","facts":{"fixed":"9.5.17","introduced":null,"published":"2019-05-09"}},{"major":"9.6","fixed_version":"9.6.13","introduced":null,"published_date":"2019-05-09","facts":{"fixed":"9.6.13","introduced":null,"published":"2019-05-09"}}],"legacy":[]}
