← Back

CVE-2024-10978

nvd nist
Published: Nov 14, 2024Modified: Jun 17, 2026

JSON object

Loading...
4.2
Vector
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N
Exploitability: 1.6 / Impact: 2.5
Source: NVD

Description

Incorrect privilege assignment in PostgreSQL allows a less-privileged application user to view or change different rows from those intended. An attack requires the application to use SET ROLE, SET SESSION AUTHORIZATION, or an equivalent feature. The problem arises when an application query uses parameters from the attacker or conveys query results to the attacker. If that query reacts to current_setting('role') or the current user ID, it may modify or return data as though the session had not used SET ROLE or SET SESSION AUTHORIZATION. The attacker does not control which incorrect user ID applies. Query text from less-privileged sources is not a concern here, because SET ROLE and SET SESSION AUTHORIZATION are not sandboxes for unvetted queries. Versions before PostgreSQL 17.1, 16.5, 15.9, 14.14, 13.17, and 12.21 are affected.

Affected (11)

1 product
Postgresql
1 product
Debian Linux
Configuration A
10 vulnerable
Vulnerable SoftwareAffected Versions
Postgresql
From 12.0 to 12.21
From 13.0 to 13.17
From 14.0 to 14.14
From 15.0 to 15.9
From 16.0 to 16.5
Version 17.0
Version 17.0 beta1
Version 17.0 beta2
Version 17.0 beta3
Version 17.0 rc1
Configuration B
1 vulnerable
Vulnerable SoftwareAffected Versions
Version 11.0

References (4)

Source: f86ef6dc-4d3a-42ad-8f28-e6d5547a5007
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing List

Timeline

No history available yet.