CVE-2023-39418

Source
https://nvd.nist.gov/vuln/detail/CVE-2023-39418
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2023-39418.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2023-39418
Aliases
Downstream
Related
Published
2023-08-11T13:15:09Z
Modified
2025-10-10T04:36:57.990701Z
Severity
  • 4.3 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N CVSS Calculator
Summary
[none]
Details

A vulnerability was found in PostgreSQL with the use of the MERGE command, which fails to test new rows against row security policies defined for UPDATE and SELECT. If UPDATE and SELECT policies forbid some rows that INSERT policies do not forbid, a user could store such rows.

References

Affected packages

Git / git.postgresql.org/git/postgresql.git

Affected ranges

Type
GIT
Repo
https://git.postgresql.org/git/postgresql.git
Events
Introduced
2a7ce2e2ce474504a707ec03e128fde66cfb8b48
Fixed
83ed1f71c88ae948a5b6ec6d2a4802cc54470102

Affected versions

Other

REL_15_0
REL_15_1
REL_15_2
REL_15_3