↑↓ select↵ open⌫ change scopeOpen full search

PG.CENTER connects PostgreSQL documentation, reference, and ecosystem knowledge. Maintained by Pigsty.

CVE-2023-2455

While CVE-2016-2193 fixed most interaction between row security and user ID changes, it missed a scenario involving function inlining. This leads to potentially incorrect policies being applied in cases where role-specific policies are used and a given query is planned under one role and then executed under other roles. This scenario can happen under security definer functions or when a common user and query is planned initially and then re-used across multiple SET ROLE s. Applying an incorrect policy may permit a user to complete otherwise-forbidden reads and modifications. This affects only databases that have used CREATE POLICY to define a row security policy. The PostgreSQL project thanks Wolfgang Walther for reporting this problem.

Version Information

Affected branchIntroducedFixed InFix Published
11—11.202023-05-11
12—12.152023-05-11
13—13.112023-05-11
14—14.82023-05-11
15—15.32023-05-11

CVSS 3.0

Overall Score4.2
Componentcore server
VectorAV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N

First published: 2023-05-11

Historical source observations

These dated records preserve the original source claims separately from the reviewed fix list.

center · 2026-10-03 12:08:35.169032+08

  • PostgreSQL 15 · Original minor coordinate: 3
  • PostgreSQL 14 · Original minor coordinate: 8

pgweb · 2026-10-03 12:08:55.967155+08

  • PostgreSQL 15 · Original minor coordinate: 3
  • PostgreSQL 14 · Original minor coordinate: 8

Original security advisory · JSON · All advisories