{"id":"CVE-2023-39418","year":2023,"sequence":39418,"component":"core server","score":3.1,"cvss_version":"3.0","vector":"AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:N","first_published":"2023-08-10","source_url":"https://www.postgresql.org/support/security/CVE-2023-39418/","facts":{"affected":{"15":"15"},"component":"core server","cvss_version":"3.0","description_en":"PostgreSQL 15 introduced the MERGE command, which fails to test new rows against row security policies defined for UPDATE and SELECT . If UPDATE and SELECT policies forbid some row that INSERT policies do not forbid, a user could store such rows. Subsequent consequences are application-dependent. This affects only databases that have used CREATE POLICY to define a row security policy.\n\nThe PostgreSQL project thanks Dean Rasheed for reporting this problem.","first_published":"2023-08-10","fixed":{"15":"15.4"},"id":"CVE-2023-39418","introduced":{},"published":{"15":"2023-08-10"},"score":3.1,"title":"MERGE fails to enforce UPDATE or SELECT row security policies","url":"https://www.postgresql.org/support/security/CVE-2023-39418/","vector":"AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:N"},"reviewed_hash":"6a65a7884245936f6adaef8709d290d460e999dfce1ad78734fa7c9a324ed325","source_hash":"965b9e2323feab543f3cbeb74c418c3a5b43cbefc6594d2862ff0d24dcf8e6a2","text":{"locale":"zh-Hans","title":"MERGE 未能强制执行 UPDATE 或 SELECT 行级安全策略","description":"MERGE 未能强制执行 UPDATE 或 SELECT 行级安全策略","details":null,"format":"markdown","provenance":{"identity":"immutable_cve_code","sources":[{"observed_at":"2026-10-03 12:08:35.169032+08","raw":{"component":"core server","cve":"2023-39418","cvenumber":202339418,"description":"MERGE 未能强制执行 UPDATE 或 SELECT 行级安全策略","details":null,"detailslink":"https://access.redhat.com/security/cve/CVE-2023-39418","id":20,"legacyscore":"","newspost_id":null,"public":true,"vector":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:N"},"source":"center","source_id":20,"source_table_sha256":"b57ee28b2263464208af0ccf7512b31f0c1ab7140d12dda09a0c87de341f1372"},{"observed_at":"2026-10-03 12:08:55.967155+08","raw":{"component":"core server","cve":"2023-39418","cvenumber":202339418,"description":"MERGE 未能强制执行 UPDATE 或 SELECT 行级安全策略","details":null,"detailslink":"https://access.redhat.com/security/cve/CVE-2023-39418","id":20,"legacyscore":"","newspost_id":null,"public":true,"vector":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:N"},"source":"pgweb","source_id":20,"source_table_sha256":"b57ee28b2263464208af0ccf7512b31f0c1ab7140d12dda09a0c87de341f1372"}]},"text_hash":"7e4673765aadd362a67e18965fdd3ad3137626ac90a0ba0bc4f00412201cb36e"},"locales":["en","zh-Hans"],"fixes":[{"major":"15","fixed_version":"15.4","introduced":null,"published_date":"2023-08-10","facts":{"fixed":"15.4","introduced":null,"published":"2023-08-10"}}],"legacy":[{"source":"center","source_id":20,"observed_at":"2026-10-03 12:08:35.169032+08","raw":{"id":20,"cve":"2023-39418","public":true,"vector":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:N","details":null,"component":"core server","cvenumber":202339418,"description":"MERGE 未能强制执行 UPDATE 或 SELECT 行级安全策略","detailslink":"https://access.redhat.com/security/cve/CVE-2023-39418","legacyscore":"","newspost_id":null},"fixes":[{"source_id":77,"source_version_id":28,"major":"15","fixed_minor":4,"raw":{"id":77,"patch_id":20,"version_id":28,"fixed_minor":4},"version_raw":{"id":28,"tree":15.0,"current":false,"docsgit":"","eoldate":"2027-11-11","reldate":"2026-08-13","testing":0,"supported":true,"docsloaded":"2026-09-27T08:10:47.078613+08:00","latestminor":19,"firstreldate":"2022-10-13"}}]},{"source":"pgweb","source_id":20,"observed_at":"2026-10-03 12:08:55.967155+08","raw":{"id":20,"cve":"2023-39418","public":true,"vector":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:N","details":null,"component":"core server","cvenumber":202339418,"description":"MERGE 未能强制执行 UPDATE 或 SELECT 行级安全策略","detailslink":"https://access.redhat.com/security/cve/CVE-2023-39418","legacyscore":"","newspost_id":null},"fixes":[{"source_id":77,"source_version_id":28,"major":"15","fixed_minor":4,"raw":{"id":77,"patch_id":20,"version_id":28,"fixed_minor":4},"version_raw":{"id":28,"tree":15.0,"current":false,"docsgit":"","eoldate":"2027-11-11","reldate":"2026-08-13","testing":0,"supported":true,"docsloaded":"2026-09-27T00:10:45.258078+08:00","latestminor":19,"firstreldate":"2022-10-13"}}]}]}
