{"id":"CVE-2019-10210","year":2019,"sequence":10210,"component":"packaging","score":6.7,"cvss_version":"3.0","vector":"AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H","first_published":"2019-08-08","source_url":"https://www.postgresql.org/support/security/CVE-2019-10210/","facts":{"affected":{"10":"10","11":"11","9.4":"9.4","9.5":"9.5","9.6":"9.6"},"component":"packaging","cvss_version":"3.0","description_en":"The EnterpriseDB Windows installer writes a password to a temporary file in its installation directory, creates initial databases, and deletes the file. During those seconds while the file exists, a local attacker can read the PostgreSQL superuser password from the file.\n\nThe PostgreSQL project thanks Noah Misch for reporting this problem.","first_published":"2019-08-08","fixed":{"10":"10.10","11":"11.5","9.4":"9.4.24","9.5":"9.5.19","9.6":"9.6.15"},"id":"CVE-2019-10210","introduced":{},"published":{"10":"2019-08-08","11":"2019-08-08","9.4":"2019-08-08","9.5":"2019-08-08","9.6":"2019-08-08"},"score":6.7,"title":"Windows installer writes superuser password to unprotected temporary file","url":"https://www.postgresql.org/support/security/CVE-2019-10210/","vector":"AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H"},"reviewed_hash":"6a65a7884245936f6adaef8709d290d460e999dfce1ad78734fa7c9a324ed325","source_hash":"965b9e2323feab543f3cbeb74c418c3a5b43cbefc6594d2862ff0d24dcf8e6a2","text":{"locale":"en","title":"Windows installer writes superuser password to unprotected temporary file","description":"The EnterpriseDB Windows installer writes a password to a temporary file in its installation directory, creates initial databases, and deletes the file. During those seconds while the file exists, a local attacker can read the PostgreSQL superuser password from the file.\n\nThe PostgreSQL project thanks Noah Misch for reporting this problem.","details":null,"format":"plain","provenance":{"fetched_at":"2026-09-26T10:56:06+00:00","path":"compare/security.json","root":"source-data","sha256":"6a65a7884245936f6adaef8709d290d460e999dfce1ad78734fa7c9a324ed325","source_archive_sha256":"8d8ad63581e1d27b3a0f995ded3feb81c265e38b2ac652eb22f022f52c2240ec","source_revision":"004bc292ee31c11f9a41ab007e9d8116bce29a71","source_url":"https://www.postgresql.org/support/security/"},"text_hash":"b0a4ab62201b26839918535b0922875637796cc104a04cd038ccd5fd0afe1855"},"locales":["en"],"fixes":[{"major":"10","fixed_version":"10.10","introduced":null,"published_date":"2019-08-08","facts":{"fixed":"10.10","introduced":null,"published":"2019-08-08"}},{"major":"11","fixed_version":"11.5","introduced":null,"published_date":"2019-08-08","facts":{"fixed":"11.5","introduced":null,"published":"2019-08-08"}},{"major":"9.4","fixed_version":"9.4.24","introduced":null,"published_date":"2019-08-08","facts":{"fixed":"9.4.24","introduced":null,"published":"2019-08-08"}},{"major":"9.5","fixed_version":"9.5.19","introduced":null,"published_date":"2019-08-08","facts":{"fixed":"9.5.19","introduced":null,"published":"2019-08-08"}},{"major":"9.6","fixed_version":"9.6.15","introduced":null,"published_date":"2019-08-08","facts":{"fixed":"9.6.15","introduced":null,"published":"2019-08-08"}}],"legacy":[]}
