{"id":"CVE-2024-10976","year":2024,"sequence":10976,"component":"core server","score":4.2,"cvss_version":"3.0","vector":"AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N","first_published":"2024-11-14","source_url":"https://www.postgresql.org/support/security/CVE-2024-10976/","facts":{"affected":{"12":"12","13":"13","14":"14","15":"15","16":"16","17":"17"},"affected_ranges":[{"from":"0","until":"12.21"},{"from":"13","until":"13.17"},{"from":"14","until":"14.14"},{"from":"15","until":"15.9"},{"from":"16","until":"16.5"},{"from":"17","until":"17.1"}],"cna_url":"https://cveawg.mitre.org/api/cve/CVE-2024-10976","component":"core server","cvss_version":"3.0","description_en":"Incomplete tracking in PostgreSQL of tables with row security allows a reused query to view or change different rows from those intended. CVE-2023-2455 and CVE-2016-2193 fixed most interaction between row security and user ID changes. They missed cases where a subquery, WITH query, security invoker view, or SQL-language function references a table with a row-level security policy. This has the same consequences as the two earlier CVEs. That is to say, it leads to potentially incorrect policies being applied in cases where role-specific policies are used and a given query is planned under one role and then executed under other roles. This scenario can happen under security definer functions or when a common user and query is planned initially and then re-used across multiple SET ROLEs.\n\nApplying an incorrect policy may permit a user to complete otherwise-forbidden reads and modifications. This affects only databases that have used CREATE POLICY to define a row security policy. An attacker must tailor an attack to a particular application's pattern of query plan reuse, user ID changes, and role-specific row security policies. Versions before PostgreSQL 17.1, 16.5, 15.9, 14.14, 13.17, and 12.21 are affected.","first_published":"2024-11-14","fixed":{"12":"12.21","13":"13.17","14":"14.14","15":"15.9","16":"16.5","17":"17.1"},"id":"CVE-2024-10976","introduced":{},"published":{"12":"2024-11-14","13":"2024-11-14","14":"2024-11-14","15":"2024-11-14","16":"2024-11-14","17":"2024-11-14"},"score":4.2,"title":"PostgreSQL row security below e.g. subqueries disregards user ID changes","url":"https://www.postgresql.org/support/security/CVE-2024-10976/","vector":"AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N"},"reviewed_hash":"6a65a7884245936f6adaef8709d290d460e999dfce1ad78734fa7c9a324ed325","source_hash":"965b9e2323feab543f3cbeb74c418c3a5b43cbefc6594d2862ff0d24dcf8e6a2","text":{"locale":"zh-Hans","title":"PostgreSQL 行级安全在子查询等场景下会忽略用户 ID 变化","description":"PostgreSQL 行级安全在子查询等场景下会忽略用户 ID 变化","details":null,"format":"markdown","provenance":{"identity":"immutable_cve_code","sources":[{"observed_at":"2026-10-03 12:08:35.169032+08","raw":{"component":"core server","cve":"2024-10976","cvenumber":202410976,"description":"PostgreSQL 行级安全在子查询等场景下会忽略用户 ID 变化","details":null,"detailslink":"https://access.redhat.com/security/cve/CVE-2024-10976","id":16,"legacyscore":"","newspost_id":null,"public":true,"vector":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N"},"source":"center","source_id":16,"source_table_sha256":"b57ee28b2263464208af0ccf7512b31f0c1ab7140d12dda09a0c87de341f1372"},{"observed_at":"2026-10-03 12:08:55.967155+08","raw":{"component":"core server","cve":"2024-10976","cvenumber":202410976,"description":"PostgreSQL 行级安全在子查询等场景下会忽略用户 ID 变化","details":null,"detailslink":"https://access.redhat.com/security/cve/CVE-2024-10976","id":16,"legacyscore":"","newspost_id":null,"public":true,"vector":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N"},"source":"pgweb","source_id":16,"source_table_sha256":"b57ee28b2263464208af0ccf7512b31f0c1ab7140d12dda09a0c87de341f1372"}]},"text_hash":"43d88fbc5eab0ee962d15bde2b7cf3d1edd7603a86a3891041bb2885f775e092"},"locales":["en","zh-Hans"],"fixes":[{"major":"12","fixed_version":"12.21","introduced":null,"published_date":"2024-11-14","facts":{"fixed":"12.21","introduced":null,"published":"2024-11-14"}},{"major":"13","fixed_version":"13.17","introduced":null,"published_date":"2024-11-14","facts":{"fixed":"13.17","introduced":null,"published":"2024-11-14"}},{"major":"14","fixed_version":"14.14","introduced":null,"published_date":"2024-11-14","facts":{"fixed":"14.14","introduced":null,"published":"2024-11-14"}},{"major":"15","fixed_version":"15.9","introduced":null,"published_date":"2024-11-14","facts":{"fixed":"15.9","introduced":null,"published":"2024-11-14"}},{"major":"16","fixed_version":"16.5","introduced":null,"published_date":"2024-11-14","facts":{"fixed":"16.5","introduced":null,"published":"2024-11-14"}},{"major":"17","fixed_version":"17.1","introduced":null,"published_date":"2024-11-14","facts":{"fixed":"17.1","introduced":null,"published":"2024-11-14"}}],"legacy":[{"source":"center","source_id":16,"observed_at":"2026-10-03 12:08:35.169032+08","raw":{"id":16,"cve":"2024-10976","public":true,"vector":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N","details":null,"component":"core server","cvenumber":202410976,"description":"PostgreSQL 行级安全在子查询等场景下会忽略用户 ID 变化","detailslink":"https://access.redhat.com/security/cve/CVE-2024-10976","legacyscore":"","newspost_id":null},"fixes":[{"source_id":64,"source_version_id":30,"major":"17","fixed_minor":1,"raw":{"id":64,"patch_id":16,"version_id":30,"fixed_minor":1},"version_raw":{"id":30,"tree":17.0,"current":false,"docsgit":"","eoldate":"2029-11-08","reldate":"2026-08-13","testing":0,"supported":true,"docsloaded":"2026-09-27T08:10:47.078613+08:00","latestminor":11,"firstreldate":"2024-09-26"}},{"source_id":65,"source_version_id":29,"major":"16","fixed_minor":5,"raw":{"id":65,"patch_id":16,"version_id":29,"fixed_minor":5},"version_raw":{"id":29,"tree":16.0,"current":false,"docsgit":"","eoldate":"2028-11-09","reldate":"2026-08-13","testing":0,"supported":true,"docsloaded":"2026-09-27T08:10:47.078613+08:00","latestminor":15,"firstreldate":"2023-09-14"}},{"source_id":66,"source_version_id":28,"major":"15","fixed_minor":9,"raw":{"id":66,"patch_id":16,"version_id":28,"fixed_minor":9},"version_raw":{"id":28,"tree":15.0,"current":false,"docsgit":"","eoldate":"2027-11-11","reldate":"2026-08-13","testing":0,"supported":true,"docsloaded":"2026-09-27T08:10:47.078613+08:00","latestminor":19,"firstreldate":"2022-10-13"}},{"source_id":67,"source_version_id":27,"major":"14","fixed_minor":14,"raw":{"id":67,"patch_id":16,"version_id":27,"fixed_minor":14},"version_raw":{"id":27,"tree":14.0,"current":false,"docsgit":"","eoldate":"2026-11-12","reldate":"2026-08-13","testing":0,"supported":true,"docsloaded":"2026-09-27T08:10:47.078613+08:00","latestminor":24,"firstreldate":"2021-09-30"}}]},{"source":"pgweb","source_id":16,"observed_at":"2026-10-03 12:08:55.967155+08","raw":{"id":16,"cve":"2024-10976","public":true,"vector":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N","details":null,"component":"core server","cvenumber":202410976,"description":"PostgreSQL 行级安全在子查询等场景下会忽略用户 ID 变化","detailslink":"https://access.redhat.com/security/cve/CVE-2024-10976","legacyscore":"","newspost_id":null},"fixes":[{"source_id":64,"source_version_id":30,"major":"17","fixed_minor":1,"raw":{"id":64,"patch_id":16,"version_id":30,"fixed_minor":1},"version_raw":{"id":30,"tree":17.0,"current":false,"docsgit":"","eoldate":"2029-11-08","reldate":"2026-08-13","testing":0,"supported":true,"docsloaded":"2026-09-27T00:10:45.258078+08:00","latestminor":11,"firstreldate":"2024-09-26"}},{"source_id":65,"source_version_id":29,"major":"16","fixed_minor":5,"raw":{"id":65,"patch_id":16,"version_id":29,"fixed_minor":5},"version_raw":{"id":29,"tree":16.0,"current":false,"docsgit":"","eoldate":"2028-11-09","reldate":"2026-08-13","testing":0,"supported":true,"docsloaded":"2026-09-27T00:10:45.258078+08:00","latestminor":15,"firstreldate":"2023-09-14"}},{"source_id":66,"source_version_id":28,"major":"15","fixed_minor":9,"raw":{"id":66,"patch_id":16,"version_id":28,"fixed_minor":9},"version_raw":{"id":28,"tree":15.0,"current":false,"docsgit":"","eoldate":"2027-11-11","reldate":"2026-08-13","testing":0,"supported":true,"docsloaded":"2026-09-27T00:10:45.258078+08:00","latestminor":19,"firstreldate":"2022-10-13"}},{"source_id":67,"source_version_id":27,"major":"14","fixed_minor":14,"raw":{"id":67,"patch_id":16,"version_id":27,"fixed_minor":14},"version_raw":{"id":27,"tree":14.0,"current":false,"docsgit":"","eoldate":"2026-11-12","reldate":"2026-08-13","testing":0,"supported":true,"docsloaded":"2026-09-27T00:10:45.258078+08:00","latestminor":24,"firstreldate":"2021-09-30"}}]}]}
