{"id":"CVE-2023-2455","year":2023,"sequence":2455,"component":"core server","score":4.2,"cvss_version":"3.0","vector":"AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N","first_published":"2023-05-11","source_url":"https://www.postgresql.org/support/security/CVE-2023-2455/","facts":{"affected":{"11":"11","12":"12","13":"13","14":"14","15":"15"},"component":"core server","cvss_version":"3.0","description_en":"While CVE-2016-2193 fixed most interaction between row security and user ID changes, it missed a scenario involving function inlining. This leads to potentially incorrect policies being applied in cases where role-specific policies are used and a given query is planned under one role and then executed under other roles. This scenario can happen under security definer functions or when a common user and query is planned initially and then re-used across multiple SET ROLE s. Applying an incorrect policy may permit a user to complete otherwise-forbidden reads and modifications. This affects only databases that have used CREATE POLICY to define a row security policy.\n\nThe PostgreSQL project thanks Wolfgang Walther for reporting this problem.","first_published":"2023-05-11","fixed":{"11":"11.20","12":"12.15","13":"13.11","14":"14.8","15":"15.3"},"id":"CVE-2023-2455","introduced":{},"published":{"11":"2023-05-11","12":"2023-05-11","13":"2023-05-11","14":"2023-05-11","15":"2023-05-11"},"score":4.2,"title":"Row security policies disregard user ID changes after inlining","url":"https://www.postgresql.org/support/security/CVE-2023-2455/","vector":"AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N"},"reviewed_hash":"6a65a7884245936f6adaef8709d290d460e999dfce1ad78734fa7c9a324ed325","source_hash":"965b9e2323feab543f3cbeb74c418c3a5b43cbefc6594d2862ff0d24dcf8e6a2","text":{"locale":"zh-Hans","title":"行级安全策略在内联后会忽略用户 ID 变化","description":"行级安全策略在内联后会忽略用户 ID 变化","details":null,"format":"markdown","provenance":{"identity":"immutable_cve_code","sources":[{"observed_at":"2026-10-03 12:08:35.169032+08","raw":{"component":"core server","cve":"2023-2455","cvenumber":202302455,"description":"行级安全策略在内联后会忽略用户 ID 变化","details":null,"detailslink":"https://access.redhat.com/security/cve/CVE-2023-2455","id":25,"legacyscore":"","newspost_id":null,"public":true,"vector":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N"},"source":"center","source_id":25,"source_table_sha256":"b57ee28b2263464208af0ccf7512b31f0c1ab7140d12dda09a0c87de341f1372"},{"observed_at":"2026-10-03 12:08:55.967155+08","raw":{"component":"core server","cve":"2023-2455","cvenumber":202302455,"description":"行级安全策略在内联后会忽略用户 ID 变化","details":null,"detailslink":"https://access.redhat.com/security/cve/CVE-2023-2455","id":25,"legacyscore":"","newspost_id":null,"public":true,"vector":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N"},"source":"pgweb","source_id":25,"source_table_sha256":"b57ee28b2263464208af0ccf7512b31f0c1ab7140d12dda09a0c87de341f1372"}]},"text_hash":"d4d56525fcbfe473ecb0967dbf5df44fe0d3d402a051cbed70591d7baf8f91ce"},"locales":["en","zh-Hans"],"fixes":[{"major":"11","fixed_version":"11.20","introduced":null,"published_date":"2023-05-11","facts":{"fixed":"11.20","introduced":null,"published":"2023-05-11"}},{"major":"12","fixed_version":"12.15","introduced":null,"published_date":"2023-05-11","facts":{"fixed":"12.15","introduced":null,"published":"2023-05-11"}},{"major":"13","fixed_version":"13.11","introduced":null,"published_date":"2023-05-11","facts":{"fixed":"13.11","introduced":null,"published":"2023-05-11"}},{"major":"14","fixed_version":"14.8","introduced":null,"published_date":"2023-05-11","facts":{"fixed":"14.8","introduced":null,"published":"2023-05-11"}},{"major":"15","fixed_version":"15.3","introduced":null,"published_date":"2023-05-11","facts":{"fixed":"15.3","introduced":null,"published":"2023-05-11"}}],"legacy":[{"source":"center","source_id":25,"observed_at":"2026-10-03 12:08:35.169032+08","raw":{"id":25,"cve":"2023-2455","public":true,"vector":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N","details":null,"component":"core server","cvenumber":202302455,"description":"行级安全策略在内联后会忽略用户 ID 变化","detailslink":"https://access.redhat.com/security/cve/CVE-2023-2455","legacyscore":"","newspost_id":null},"fixes":[{"source_id":89,"source_version_id":28,"major":"15","fixed_minor":3,"raw":{"id":89,"patch_id":25,"version_id":28,"fixed_minor":3},"version_raw":{"id":28,"tree":15.0,"current":false,"docsgit":"","eoldate":"2027-11-11","reldate":"2026-08-13","testing":0,"supported":true,"docsloaded":"2026-09-27T08:10:47.078613+08:00","latestminor":19,"firstreldate":"2022-10-13"}},{"source_id":90,"source_version_id":27,"major":"14","fixed_minor":8,"raw":{"id":90,"patch_id":25,"version_id":27,"fixed_minor":8},"version_raw":{"id":27,"tree":14.0,"current":false,"docsgit":"","eoldate":"2026-11-12","reldate":"2026-08-13","testing":0,"supported":true,"docsloaded":"2026-09-27T08:10:47.078613+08:00","latestminor":24,"firstreldate":"2021-09-30"}}]},{"source":"pgweb","source_id":25,"observed_at":"2026-10-03 12:08:55.967155+08","raw":{"id":25,"cve":"2023-2455","public":true,"vector":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N","details":null,"component":"core server","cvenumber":202302455,"description":"行级安全策略在内联后会忽略用户 ID 变化","detailslink":"https://access.redhat.com/security/cve/CVE-2023-2455","legacyscore":"","newspost_id":null},"fixes":[{"source_id":89,"source_version_id":28,"major":"15","fixed_minor":3,"raw":{"id":89,"patch_id":25,"version_id":28,"fixed_minor":3},"version_raw":{"id":28,"tree":15.0,"current":false,"docsgit":"","eoldate":"2027-11-11","reldate":"2026-08-13","testing":0,"supported":true,"docsloaded":"2026-09-27T00:10:45.258078+08:00","latestminor":19,"firstreldate":"2022-10-13"}},{"source_id":90,"source_version_id":27,"major":"14","fixed_minor":8,"raw":{"id":90,"patch_id":25,"version_id":27,"fixed_minor":8},"version_raw":{"id":27,"tree":14.0,"current":false,"docsgit":"","eoldate":"2026-11-12","reldate":"2026-08-13","testing":0,"supported":true,"docsloaded":"2026-09-27T00:10:45.258078+08:00","latestminor":24,"firstreldate":"2021-09-30"}}]}]}
