CVE-2024-4317
Public on 2024-05-10
Modified on 2024-05-10
Description
postgresql: PostgreSQL pg_stats_ext and pg_stats_ext_exprs lack authorization checks
Severity
CVSS v3 Base Score
See breakdown
Affected Packages
Platform | Package | Release Date | Advisory | Status |
---|---|---|---|---|
Amazon Linux 2 - Core | postgresql | Not Affected | ||
Amazon Linux 2 - Postgresql12 Extra | postgresql | Not Affected | ||
Amazon Linux 2 - Postgresql13 Extra | postgresql | Not Affected | ||
Amazon Linux 2 - Postgresql14 Extra | postgresql | 2024-06-06 | ALAS2POSTGRESQL14-2024-011 | Fixed |
Amazon Linux 2023 | postgresql15 | 2024-06-06 | ALAS2023-2024-635 | Fixed |
Amazon Linux 1 | postgresql8 | No Fix Planned | ||
Amazon Linux 1 | postgresql92 | No Fix Planned | ||
Amazon Linux 1 | postgresql93 | No Fix Planned | ||
Amazon Linux 1 | postgresql94 | No Fix Planned | ||
Amazon Linux 1 | postgresql95 | No Fix Planned | ||
Amazon Linux 1 | postgresql96 | No Fix Planned |
CVSS Scores
Score Type | Score | Vector | |
---|---|---|---|
Amazon Linux | CVSSv3 | 3.1 | CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N |
NVD | CVSSv3 | 3.1 | CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N |