A flaw was found in PostgreSQL's "ALTER ... DEPENDS ON EXTENSION", where sub-commands did not perform authorization checks. An authenticated attacker could use this flaw in certain configurations to perform drop objects such as function, triggers, et al., leading to database corruption. This issue affects PostgreSQL versions before 12.2, before 11.7, before 10.12 and before 9.6.17.
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: redhat

Published: 2020-03-17T15:28:24

Updated: 2020-08-17T17:06:13

Reserved: 2019-11-27T00:00:00


Link: CVE-2020-1720

JSON object: View

cve-icon NVD Information

Status : Modified

Published: 2020-03-17T16:15:11.127

Modified: 2023-11-07T03:19:29.340


Link: CVE-2020-1720

JSON object: View

cve-icon Redhat Information

No data.