{"id":"CVE-2024-4317","year":2024,"sequence":4317,"component":"core server","score":3.1,"cvss_version":"3.0","vector":"AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N","first_published":"2024-05-09","source_url":"https://www.postgresql.org/support/security/CVE-2024-4317/","facts":{"affected":{"14":"14","15":"15","16":"16"},"affected_ranges":[{"from":"14","until":"14.12"},{"from":"15","until":"15.7"},{"from":"16","until":"16.3"}],"cna_url":"https://cveawg.mitre.org/api/cve/CVE-2024-4317","component":"core server","cvss_version":"3.0","description_en":"Missing authorization in PostgreSQL built-in views pg_stats_ext and pg_stats_ext_exprs allows an unprivileged database user to read most common values and other statistics from CREATE STATISTICS commands of other users. The most common values may reveal column values the eavesdropper could not otherwise read or results of functions they cannot execute. Installing an unaffected version only fixes fresh PostgreSQL installations, namely those that are created with the initdb utility after installing that version. Current PostgreSQL installations will remain vulnerable until they follow the instructions in the release notes, which are provided as a convenience in the below section. Within major versions 14-16, minor versions before PostgreSQL 16.3, 15.7, and 14.12 are affected. Versions before PostgreSQL 14 are unaffected.\n\nThis fix only fixes fresh PostgreSQL installations, namely those that are created with the initdb utility after this fix is applied. If you have a current PostgreSQL installation and are concerned about this issue, please use the following remediation steps to fix the issue:\n\nFrom the above URLs, you can click the URL that says \"raw\" to download a version that you can copy and paste.\n\nBe sure to use the script appropriate to your PostgreSQL major version. If you do not see this file, either your version is not vulnerable (only PostgreSQL 14, 15, and 16 are affected) or your minor version is too old to have the fix.\n\n\\i /usr/share/postgresql/fix-CVE-2024-4317.sql\n\nALTER DATABASE template0 WITH ALLOW_CONNECTIONS true;\n\nAfter executing the fix-CVE-2024-4317.sql script in template0 and template1 , you should revoke the ability for template0 to accept connections. You can do this with the following command:\n\nALTER DATABASE template0 WITH ALLOW_CONNECTIONS false;\n\nThe PostgreSQL project thanks Lukas Fittl for reporting this problem.","first_published":"2024-05-09","fixed":{"14":"14.12","15":"15.7","16":"16.3"},"id":"CVE-2024-4317","introduced":{},"published":{"14":"2024-05-09","15":"2024-05-09","16":"2024-05-09"},"score":3.1,"title":"Restrict visibility of \"pg_stats_ext\" and \"pg_stats_ext_exprs\" entries to the table owner","url":"https://www.postgresql.org/support/security/CVE-2024-4317/","vector":"AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N"},"reviewed_hash":"6a65a7884245936f6adaef8709d290d460e999dfce1ad78734fa7c9a324ed325","source_hash":"965b9e2323feab543f3cbeb74c418c3a5b43cbefc6594d2862ff0d24dcf8e6a2","text":{"locale":"zh-Hans","title":"将 pg_stats_ext 和 pg_stats_ext_exprs 条目的可见性限制为仅表所有者可见","description":"将 pg_stats_ext 和 pg_stats_ext_exprs 条目的可见性限制为仅表所有者可见","details":null,"format":"markdown","provenance":{"identity":"immutable_cve_code","sources":[{"observed_at":"2026-10-03 12:08:35.169032+08","raw":{"component":"core server","cve":"2024-4317","cvenumber":202404317,"description":"将 pg_stats_ext 和 pg_stats_ext_exprs 条目的可见性限制为仅表所有者可见","details":null,"detailslink":"https://access.redhat.com/security/cve/CVE-2024-4317","id":18,"legacyscore":"","newspost_id":null,"public":true,"vector":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N"},"source":"center","source_id":18,"source_table_sha256":"b57ee28b2263464208af0ccf7512b31f0c1ab7140d12dda09a0c87de341f1372"},{"observed_at":"2026-10-03 12:08:55.967155+08","raw":{"component":"core server","cve":"2024-4317","cvenumber":202404317,"description":"将 pg_stats_ext 和 pg_stats_ext_exprs 条目的可见性限制为仅表所有者可见","details":null,"detailslink":"https://access.redhat.com/security/cve/CVE-2024-4317","id":18,"legacyscore":"","newspost_id":null,"public":true,"vector":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N"},"source":"pgweb","source_id":18,"source_table_sha256":"b57ee28b2263464208af0ccf7512b31f0c1ab7140d12dda09a0c87de341f1372"}]},"text_hash":"73ce0100bba73c7e80d73b14ad96ade9b3cc673d87ce20fb60912c8e8deb2877"},"locales":["en","zh-Hans"],"fixes":[{"major":"14","fixed_version":"14.12","introduced":null,"published_date":"2024-05-09","facts":{"fixed":"14.12","introduced":null,"published":"2024-05-09"}},{"major":"15","fixed_version":"15.7","introduced":null,"published_date":"2024-05-09","facts":{"fixed":"15.7","introduced":null,"published":"2024-05-09"}},{"major":"16","fixed_version":"16.3","introduced":null,"published_date":"2024-05-09","facts":{"fixed":"16.3","introduced":null,"published":"2024-05-09"}}],"legacy":[{"source":"center","source_id":18,"observed_at":"2026-10-03 12:08:35.169032+08","raw":{"id":18,"cve":"2024-4317","public":true,"vector":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N","details":null,"component":"core server","cvenumber":202404317,"description":"将 pg_stats_ext 和 pg_stats_ext_exprs 条目的可见性限制为仅表所有者可见","detailslink":"https://access.redhat.com/security/cve/CVE-2024-4317","legacyscore":"","newspost_id":null},"fixes":[{"source_id":71,"source_version_id":29,"major":"16","fixed_minor":3,"raw":{"id":71,"patch_id":18,"version_id":29,"fixed_minor":3},"version_raw":{"id":29,"tree":16.0,"current":false,"docsgit":"","eoldate":"2028-11-09","reldate":"2026-08-13","testing":0,"supported":true,"docsloaded":"2026-09-27T08:10:47.078613+08:00","latestminor":15,"firstreldate":"2023-09-14"}},{"source_id":72,"source_version_id":28,"major":"15","fixed_minor":7,"raw":{"id":72,"patch_id":18,"version_id":28,"fixed_minor":7},"version_raw":{"id":28,"tree":15.0,"current":false,"docsgit":"","eoldate":"2027-11-11","reldate":"2026-08-13","testing":0,"supported":true,"docsloaded":"2026-09-27T08:10:47.078613+08:00","latestminor":19,"firstreldate":"2022-10-13"}},{"source_id":73,"source_version_id":27,"major":"14","fixed_minor":12,"raw":{"id":73,"patch_id":18,"version_id":27,"fixed_minor":12},"version_raw":{"id":27,"tree":14.0,"current":false,"docsgit":"","eoldate":"2026-11-12","reldate":"2026-08-13","testing":0,"supported":true,"docsloaded":"2026-09-27T08:10:47.078613+08:00","latestminor":24,"firstreldate":"2021-09-30"}}]},{"source":"pgweb","source_id":18,"observed_at":"2026-10-03 12:08:55.967155+08","raw":{"id":18,"cve":"2024-4317","public":true,"vector":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N","details":null,"component":"core server","cvenumber":202404317,"description":"将 pg_stats_ext 和 pg_stats_ext_exprs 条目的可见性限制为仅表所有者可见","detailslink":"https://access.redhat.com/security/cve/CVE-2024-4317","legacyscore":"","newspost_id":null},"fixes":[{"source_id":71,"source_version_id":29,"major":"16","fixed_minor":3,"raw":{"id":71,"patch_id":18,"version_id":29,"fixed_minor":3},"version_raw":{"id":29,"tree":16.0,"current":false,"docsgit":"","eoldate":"2028-11-09","reldate":"2026-08-13","testing":0,"supported":true,"docsloaded":"2026-09-27T00:10:45.258078+08:00","latestminor":15,"firstreldate":"2023-09-14"}},{"source_id":72,"source_version_id":28,"major":"15","fixed_minor":7,"raw":{"id":72,"patch_id":18,"version_id":28,"fixed_minor":7},"version_raw":{"id":28,"tree":15.0,"current":false,"docsgit":"","eoldate":"2027-11-11","reldate":"2026-08-13","testing":0,"supported":true,"docsloaded":"2026-09-27T00:10:45.258078+08:00","latestminor":19,"firstreldate":"2022-10-13"}},{"source_id":73,"source_version_id":27,"major":"14","fixed_minor":12,"raw":{"id":73,"patch_id":18,"version_id":27,"fixed_minor":12},"version_raw":{"id":27,"tree":14.0,"current":false,"docsgit":"","eoldate":"2026-11-12","reldate":"2026-08-13","testing":0,"supported":true,"docsloaded":"2026-09-27T00:10:45.258078+08:00","latestminor":24,"firstreldate":"2021-09-30"}}]}]}
