VYPR

Bitnami package

postgresql

pkg:bitnami/postgresql

Vulnerabilities (58)

  • CVE-2025-8713LowAug 14, 2025
    affected < 13.22.0fixed 13.22.0

    PostgreSQL optimizer statistics allow a user to read sampled data within a view that the user cannot access. Separately, statistics allow a user to read sampled data that a row security policy intended to hide. PostgreSQL maintains statistics for tables by sampling data availab

  • CVE-2025-4207MedMay 8, 2025
    affected < 13.21.0fixed 13.21.0

    Buffer over-read in PostgreSQL GB18030 encoding validation allows a database input provider to achieve temporary denial of service on platforms where a 1-byte over-read can elicit process termination. This affects the database server and also libpq. Versions before PostgreSQL 1

  • CVE-2025-1094HigFeb 13, 2025
    affected < 13.19.0fixed 13.19.0

    Improper neutralization of quoting syntax in PostgreSQL libpq functions PQescapeLiteral(), PQescapeIdentifier(), PQescapeString(), and PQescapeStringConn() allows a database input provider to achieve SQL injection in certain usage patterns. Specifically, SQL injection requires t

  • CVE-2024-10979Nov 14, 2024
    affected < 13.17.0fixed 13.17.0

    Incorrect control of environment variables in PostgreSQL PL/Perl allows an unprivileged database user to change sensitive process environment variables (e.g. PATH). That often suffices to enable arbitrary code execution, even if the attacker lacks a database server operating sys

  • CVE-2024-10978Nov 14, 2024
    affected < 12.21.0fixed 12.21.0

    Incorrect privilege assignment in PostgreSQL allows a less-privileged application user to view or change different rows from those intended. An attack requires the application to use SET ROLE, SET SESSION AUTHORIZATION, or an equivalent feature. The problem arises when an appli

  • CVE-2024-10977Nov 14, 2024
    affected < 12.21.0fixed 12.21.0

    Client use of server error message in PostgreSQL allows a server not trusted under current SSL or GSS settings to furnish arbitrary non-NUL bytes to the libpq application. For example, a man-in-the-middle attacker could send a long error message that a human or screen-scraper us

  • CVE-2024-10976Nov 14, 2024
    affected < 13.17.0fixed 13.17.0

    Incomplete tracking in PostgreSQL of tables with row security allows a reused query to view or change different rows from those intended. CVE-2023-2455 and CVE-2016-2193 fixed most interaction between row security and user ID changes. They missed cases where a subquery, WITH qu

  • CVE-2024-7348Aug 8, 2024
    affected < 12.20.0fixed 12.20.0

    Time-of-check Time-of-use (TOCTOU) race condition in pg_dump in PostgreSQL allows an object creator to execute arbitrary SQL functions as the user running pg_dump, which is often a superuser. The attack involves replacing another relation type with a view or foreign table. The at

  • CVE-2024-4317May 9, 2024
    affected >= 14.0.0, < 14.12.0fixed 14.12.0

    Missing authorization in PostgreSQL built-in views pg_stats_ext and pg_stats_ext_exprs allows an unprivileged database user to read most common values and other statistics from CREATE STATISTICS commands of other users. The most common values may reveal column values the eavesdro

  • CVE-2024-0985Feb 8, 2024
    affected >= 12.0.0, < 12.18.0fixed 12.18.0

    Late privilege drop in REFRESH MATERIALIZED VIEW CONCURRENTLY in PostgreSQL allows an object creator to execute arbitrary SQL functions as the command issuer. The command intends to run SQL functions as the owner of the materialized view, enabling safe refresh of untrusted materi

  • CVE-2024-24213Feb 8, 2024
    affected >= 15.1.0, <= 15.1.0

    Supabase PostgreSQL v15.1 was discovered to contain a SQL injection vulnerability via the component /pg_meta/default/query. NOTE: the vendor's position is that this is an intended feature; also, it exists in the Supabase dashboard product, not the Supabase PostgreSQL product. Spe

  • CVE-2023-5870Dec 10, 2023
    affected >= 11.0.0, < 11.22.0fixed 11.22.0

    A flaw was found in PostgreSQL involving the pg_cancel_backend role that signals background workers, including the logical replication launcher, autovacuum workers, and the autovacuum launcher. Successful exploitation requires a non-core extension with a less-resilient background

  • CVE-2023-5868Dec 10, 2023
    affected >= 11.0.0, < 11.22.0fixed 11.22.0

    A memory disclosure vulnerability was found in PostgreSQL that allows remote users to access sensitive information by exploiting certain aggregate function calls with 'unknown'-type arguments. Handling 'unknown'-type values from string literals without type designation can disclo

  • CVE-2023-5869Dec 10, 2023
    affected >= 11.0.0, < 11.22.0fixed 11.22.0

    A flaw was found in PostgreSQL that allows authenticated database users to execute arbitrary code through missing overflow checks during SQL array value modification. This issue exists due to an integer overflow during array modification where a remote user can trigger the overfl

  • CVE-2020-21469Aug 22, 2023
    affected >= 12.2.0, < 12.2.1fixed 12.2.1

    An issue was discovered in PostgreSQL 12.2 allows attackers to cause a denial of service via repeatedly sending SIGHUP signals. NOTE: this is disputed by the vendor because untrusted users cannot send SIGHUP signals; they can only be sent by a PostgreSQL superuser, a user with pg

  • CVE-2023-39418Aug 11, 2023
    affected >= 15.0.0, < 15.4.0fixed 15.4.0

    A vulnerability was found in PostgreSQL with the use of the MERGE command, which fails to test new rows against row security policies defined for UPDATE and SELECT. If UPDATE and SELECT policies forbid some rows that INSERT policies do not forbid, a user could store such rows.

  • CVE-2023-39417Aug 11, 2023
    affected >= 11.0.0, < 11.21.0fixed 11.21.0

    IN THE EXTENSION SCRIPT, a SQL Injection vulnerability was found in PostgreSQL if it uses @extowner@, @extschema@, or @extschema:...@ inside a quoting construct (dollar quoting, '', or ""). If an administrator has installed files of a vulnerable, trusted, non-bundled extension, a

  • CVE-2023-2455Jun 9, 2023
    affected >= 11.0.0, < 11.20.0fixed 11.20.0

    Row security policies disregard user ID changes after inlining; PostgreSQL could permit incorrect policies to be applied in certain cases where role-specific policies are used and a given query is planned under one role and then executed under other roles. This scenario can happe

  • CVE-2023-2454Jun 9, 2023
    affected >= 11.0.0, < 11.20.0fixed 11.20.0

    schema_element defeats protective search_path changes; It was found that certain database calls in PostgreSQL could permit an authed attacker with elevated database-level privileges to execute arbitrary code.

  • CVE-2022-41862Mar 3, 2023
    affected >= 12.0.0, < 12.14.0fixed 12.14.0

    In PostgreSQL, a modified, unauthenticated server can send an unterminated string during the establishment of Kerberos transport encryption. In certain conditions a server can cause a libpq client to over-read and report an error message containing uninitialized bytes.