Vulnerability Details CVE-2021-20229
A flaw was found in PostgreSQL in versions before 13.2. This flaw allows a user with SELECT privilege on one column to craft a special query that returns all columns of the table. The highest threat from this vulnerability is to confidentiality.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.001
EPSS Ranking 25.7%
CVSS Severity
CVSS v3 Score 4.3
CVSS v2 Score 4.0
Products affected by CVE-2021-20229
-
cpe:2.3:a:postgresql:postgresql:13.0
-
cpe:2.3:a:postgresql:postgresql:13.1
-
cpe:2.3:a:redhat:software_collections:-
-
cpe:2.3:o:fedoraproject:fedora:33
-
cpe:2.3:o:redhat:enterprise_linux:7.0
-
cpe:2.3:o:redhat:enterprise_linux:8.0