A flaw was found in postgresql. Using an INSERT ... ON CONFLICT ... DO UPDATE command on a purpose-crafted table, an authenticated database user could read arbitrary bytes of server memory. The highest threat from this vulnerability is to data confidentiality.
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2021-32028.json"
[
{
"events": [
{
"introduced": "9.6.0"
},
{
"fixed": "9.6.22"
}
]
},
{
"events": [
{
"introduced": "10.0"
},
{
"fixed": "10.17"
}
]
},
{
"events": [
{
"introduced": "11.0"
},
{
"fixed": "11.12"
}
]
},
{
"events": [
{
"introduced": "12.0"
},
{
"fixed": "12.7"
}
]
},
{
"events": [
{
"introduced": "13.0"
},
{
"fixed": "13.3"
}
]
}
]