PostgreSQL versions 8.4 - 9.6 are vulnerable to information leak in pg_user_mappings view which discloses foreign server passwords to any user having USAGE privilege on the associated foreign server.
No CVSS v3.1
Attack Vector Network
Attack Complexity Low
Privileges Required None
Scope Unchanged
Confidentiality Impact High
Integrity Impact None
Availability Impact None
User Interaction None
Access Vector Network
Access Complexity Low
Authentication None
Confidentiality Impact Partial
Integrity Impact None
Availability Impact None
AV:N/AC:L/Au:N/C:P/I:N/A:N
Vendors | Products |
---|---|
Postgresql |
|
Configuration 1 [-]
|
References
History
No history.
MITRE Information
Status: PUBLISHED
Assigner: redhat
Published: 2017-05-12T19:00:00
Updated: 2018-01-04T19:57:01
Reserved: 2017-04-05T00:00:00
Link: CVE-2017-7486
JSON object: View
NVD Information
Status : Modified
Published: 2017-05-12T19:29:00.270
Modified: 2018-01-05T02:31:51.497
Link: CVE-2017-7486
JSON object: View
Redhat Information
No data.