CVE-2023-39418

Source
https://cve.org/CVERecord?id=CVE-2023-39418
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2023-39418.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2023-39418
Aliases
Downstream
Related
Published
2023-08-11T13:15:09.963Z
Modified
2026-03-15T22:02:18.130202Z
Severity
  • 4.3 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N CVSS Calculator
Summary
[none]
Details

A vulnerability was found in PostgreSQL with the use of the MERGE command, which fails to test new rows against row security policies defined for UPDATE and SELECT. If UPDATE and SELECT policies forbid some rows that INSERT policies do not forbid, a user could store such rows.

References

Affected packages

Git /

Affected ranges

Database specific

unresolved_ranges
[
    {
        "events": [
            {
                "introduced": "15.0"
            },
            {
                "fixed": "15.4"
            }
        ]
    },
    {
        "events": [
            {
                "introduced": "0"
            },
            {
                "last_affected": "8.0"
            }
        ]
    },
    {
        "events": [
            {
                "introduced": "0"
            },
            {
                "last_affected": "9.0"
            }
        ]
    },
    {
        "events": [
            {
                "introduced": "0"
            },
            {
                "last_affected": "12.0"
            }
        ]
    }
]
source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2023-39418.json"