ZeroHour

CVE-2021-32029

CVSS 3.1
6.5 medium
EPSS
2%p73
Published
()
Modified
Description

A flaw was found in postgresql. Using an UPDATE ... RETURNING command on a purpose-crafted table, an authenticated database user could read arbitrary bytes of server memory. The highest threat from this vulnerability is to data confidentiality.

Vendors
postgresqlredhat
Products
postgresql, jboss enterprise application platform
Weakness
CWE-200, CWE-125
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

In the news

No ingested article mentions this CVE yet.