{"id":"CVE-2021-3393","year":2021,"sequence":3393,"component":"core server","score":3.1,"cvss_version":"3.0","vector":"AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N","first_published":"2021-02-11","source_url":"https://www.postgresql.org/support/security/CVE-2021-3393/","facts":{"affected":{"11":"11","12":"12","13":"13"},"component":"core server","cvss_version":"3.0","description_en":"A user having an UPDATE privilege on a partitioned table but lacking the SELECT privilege on some column may be able to acquire denied-column values from an error message. This is similar to CVE-2014-8161 , but the conditions to exploit are more rare.\n\nThe PostgreSQL project thanks Heikki Linnakangas for reporting this problem.","first_published":"2021-02-11","fixed":{"11":"11.11","12":"12.6","13":"13.2"},"id":"CVE-2021-3393","introduced":{},"published":{"11":"2021-02-11","12":"2021-02-11","13":"2021-02-11"},"score":3.1,"title":"Partition constraint violation errors leak values of denied columns","url":"https://www.postgresql.org/support/security/CVE-2021-3393/","vector":"AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N"},"reviewed_hash":"6a65a7884245936f6adaef8709d290d460e999dfce1ad78734fa7c9a324ed325","source_hash":"965b9e2323feab543f3cbeb74c418c3a5b43cbefc6594d2862ff0d24dcf8e6a2","text":null,"locales":["en"],"fixes":[{"major":"11","fixed_version":"11.11","introduced":null,"published_date":"2021-02-11","facts":{"fixed":"11.11","introduced":null,"published":"2021-02-11"}},{"major":"12","fixed_version":"12.6","introduced":null,"published_date":"2021-02-11","facts":{"fixed":"12.6","introduced":null,"published":"2021-02-11"}},{"major":"13","fixed_version":"13.2","introduced":null,"published_date":"2021-02-11","facts":{"fixed":"13.2","introduced":null,"published":"2021-02-11"}}],"legacy":[]}
