PostgreSQL 13
已停止支持 · 记录构建 13.23 · 2025-11-13
此大版本已停止支持,相关记录用于查阅历史;没有更新的安全记录不代表仍可安全运行。
- 首次正式发布
- 2020-09-24
- 支持结束
- 2025-11-13
- 已收录发布版本
- 24
- 原始发布说明条目
- 1164
手册与来源
PostgreSQL 13 本站手册 · 已加载 1065 页。
手册加载时间:2026-09-27T00:10:45.258078。
发布说明快照:2026-09-26。安全证据快照:2026-09-26。PDF 链接按本地文件是否存在提供,历史版本的语言与 HTML 手册可能不同。生命周期参见官方版本政策。
升级注意事项
跨大版本升级需要导出/恢复或 pg_upgrade 等迁移方式,应阅读沿途大版本的发布说明与目标版本手册。小版本更新也可能要求额外操作,请核对对应发布的迁移说明。官方升级政策。
13.0 的原始迁移说明
对于希望从任何先前版本迁移数据的用户,需要使用pg_dumpall进行导出/恢复,或使用pg_upgrade或逻辑复制。有关迁移到新主版本的一般信息,请参见第 18.6 节。
版本 13 包含许多可能影响与先前版本兼容性的变更。请注意以下不兼容性:
发布历史
每次发布的原始变更均独立保留。CVE 数量表示发布说明中的提及,可能包含后续纠正,不等于本次新修复漏洞数。
| 版本 | 日期/快照截止时间 | 全部变化 | BUG 修复 | 迁移条目 | 提及 CVE |
|---|---|---|---|---|---|
| 13.23 | 2025-11-13 | 43 | 22 | 0 | 2 |
| 13.22 | 2025-08-14 | 44 | 10 | 0 | 5 |
| 13.21 | 2025-05-08 | 28 | 12 | 0 | 1 |
| 13.20 | 2025-02-20 | 2 | 1 | 0 | 1 |
| 13.19 | 2025-02-13 | 45 | 26 | 0 | 1 |
| 13.18 | 2024-11-21 | 4 | 2 | 0 | 1 |
| 13.17 | 2024-11-14 | 38 | 14 | 0 | 4 |
| 13.16 | 2024-08-08 | 36 | 17 | 0 | 2 |
| 13.15 | 2024-05-09 | 35 | 15 | 0 | 0 |
| 13.14 | 2024-02-08 | 40 | 15 | 0 | 1 |
| 13.13 | 2023-11-09 | 48 | 17 | 0 | 3 |
| 13.12 | 2023-08-10 | 36 | 17 | 0 | 1 |
| 13.11 | 2023-05-11 | 55 | 28 | 0 | 2 |
| 13.10 | 2023-02-09 | 38 | 15 | 0 | 1 |
| 13.9 | 2022-11-10 | 41 | 19 | 0 | 0 |
| 13.8 | 2022-08-11 | 43 | 18 | 0 | 2 |
| 13.7 | 2022-05-12 | 38 | 20 | 0 | 1 |
| 13.6 | 2022-02-10 | 41 | 21 | 0 | 0 |
| 13.5 | 2021-11-11 | 77 | 36 | 0 | 2 |
| 13.4 | 2021-08-12 | 77 | 28 | 0 | 3 |
| 13.3 | 2021-05-13 | 48 | 27 | 0 | 3 |
| 13.2 | 2021-02-11 | 80 | 42 | 0 | 2 |
| 13.1 | 2020-11-12 | 49 | 24 | 0 | 3 |
| 13.0 | 2020-09-24 | 178 | 4 | 15 | 0 |
首次发布变化
13.0 的原始条目,包含功能和兼容性变化。类别用于浏览,不是上游原始分类。
匹配 178 / 178 条原始变更。
将 SIMILAR TO ... ESCAPE NULL 改为返回 NULL · 兼容性变化 · 迁移说明
将
SIMILAR TO ... ESCAPE NULL改为返回NULL(Tom Lane)§这一新行为符合 SQL 规范。以前,
ESCAPE为空值时,被解释为使用默认转义字符串(反斜杠字符)。这也适用于substring(。通过保持原函数不变,在旧视图中保留了以前的行为。textFROMpatternESCAPEtext)原始发布条目 ·
13.0/migration/001使 json[b]_to_tsvector() 完整检查其 string 选项的拼写 · 兼容性变化 · 迁移说明
使
json[b]_to_tsvector()完整检查其string选项的拼写(Dominik Czarnota)§原始发布条目 ·
13.0/migration/002改变非默认的effective_io_concurrency值影响并发度的方式 · 兼容性变化 · 迁移说明
改变非默认的effective_io_concurrency值影响并发度的方式(Thomas Munro)§
以前,该值在用于设置并发请求数之前会经过调整。现在直接使用该值。可以通过以下方式将旧值转换为新值:
SELECT round(sum(
OLDVALUE/ n::float)) AS newvalue FROM generate_series(1,OLDVALUE) s(n);原始发布条目 ·
13.0/migration/003不再在pg_stat_ssl和pg_stat_gssapi系统视图中显示辅助进程 · 兼容性变化 · 迁移说明
不再在pg_stat_ssl和pg_stat_gssapi系统视图中显示辅助进程(Euler Taveira)§
如果查询将这些视图与pg_stat_activity连接,并希望看到辅助进程,就需要使用左连接。
原始发布条目 ·
13.0/migration/004修复 ALTER FOREIGN TABLE ... RENAME COLUMN,使其返回更合适的命令标签 · 兼容性变化 · 迁移说明
修复
ALTER FOREIGN TABLE ... RENAME COLUMN,使其返回更合适的命令标签(Fujii Masao)§以前返回
ALTER TABLE;现在返回ALTER FOREIGN TABLE。原始发布条目 ·
13.0/migration/006修复 ALTER MATERIALIZED VIEW ... RENAME COLUMN,使其返回更合适的命令标签 · 兼容性变化 · 迁移说明
修复
ALTER MATERIALIZED VIEW ... RENAME COLUMN,使其返回更合适的命令标签(Fujii Masao)§以前返回
ALTER TABLE;现在返回ALTER MATERIALIZED VIEW。原始发布条目 ·
13.0/migration/007将配置参数 wal_keep_segments 重命名为wal_keep_size · 兼容性变化 · 迁移说明
将配置参数
wal_keep_segments重命名为wal_keep_size(Fujii Masao)§这决定为备库保留多少 WAL。它以 MB 为单位指定,而旧参数以文件数量指定。如果以前使用
wal_keep_segments,以下公式可以得到大致等价的设置:wal_keep_size = wal_keep_segments * wal_segment_size (typically 16MB)
原始发布条目 ·
13.0/migration/008移除对升级未打包扩展(9.1 之前的扩展)的支持 · 兼容性变化 · 迁移说明
移除对升级未打包扩展(9.1 之前的扩展)的支持(Tom Lane)§
CREATE EXTENSION不再支持FROM选项。任何仍使用未打包扩展的安装实例,都应在更新到 PostgreSQL 13 之前,将这些扩展升级为已打包的版本。原始发布条目 ·
13.0/migration/012移除对时区数据库中 posixrules 文件的支持 · 兼容性变化 · 迁移说明
移除对时区数据库中
posixrules文件的支持(Tom Lane)§IANA 的时区工作组已弃用此特性,这意味着它将在未来几年中逐渐从系统的时区数据库中消失。为避免时区数据更新意外引发行为变化,我们从版本 13 开始移除了 PostgreSQL 对此特性的支持。这只影响缺少显式夏令时切换规则的 POSIX 风格时区指定的行为;以前可以通过安装自定义
posixrules文件来确定切换规则,现在则使用硬编码规则。对于受影响的安装实例,建议改用地理时区名称。原始发布条目 ·
13.0/migration/013修复pageinspect的 bt_metap(),使其返回更合适、不易溢出的数据类型 · 兼容性变化 · 迁移说明
修复pageinspect的
bt_metap(),使其返回更合适、不易溢出的数据类型(Peter Geoghegan)§原始发布条目 ·
13.0/migration/015允许通过发布对分区表进行逻辑复制 · 新功能
允许通过发布对分区表进行逻辑复制(Amit Langote)§ §
以前,必须逐个复制分区。现在可以显式发布分区表,从而自动发布其所有分区。添加或移除分区时,也会将其相应地添加到发布或从发布中移除。
CREATE PUBLICATION的publish_via_partition_root选项控制分区变更是作为分区自身的变更发布,还是作为父表的变更发布。原始发布条目 ·
13.0/changes/004更高效地存储 B-树索引中的重复项 · 新功能
更高效地存储 B-树索引中的重复项(Anastasia Lubennikova,Peter Geoghegan)§
这通过只存储一次重复键,使低基数列能够高效地使用 B-树索引。使用pg_upgrade升级的用户,需要执行
REINDEX才能让现有索引使用这一特性。原始发布条目 ·
13.0/changes/007实现增量排序 · 性能改进
实现增量排序(James Coleman,Alexander Korotkov,Tomas Vondra)§ §
如果已知查询的中间结果按照所需排序顺序的一个或多个前导键排好序,则可以将前导键相同的行分批排序,只考虑剩余键即可完成额外的排序。
如有需要,可以使用enable_incremental_sort控制此行为。
原始发布条目 ·
13.0/changes/018允许hash 聚合对大型聚合结果集使用磁盘存储 · 性能改进
允许hash 聚合对大型聚合结果集使用磁盘存储(Jeff Davis)§ § §
以前,如果预计 hash 聚合使用的内存会超过work_mem,就会避免使用它。现在,即使如此也可以选择 hash 聚合计划。如果 hash 表超过
work_mem乘以hash_mem_multiplier的大小,就会溢写到磁盘。这一行为通常优于旧行为:以前,一旦选择了 hash 聚合,无论 hash 表增长到多大,都会一直保留在内存中;如果规划器估计有误,它可能变得非常大。如有需要,可以通过增大
hash_mem_multiplier来获得类似旧行为的效果。原始发布条目 ·
13.0/changes/020允许插入操作也触发自动清理中的清理活动,而不再仅由更新和删除触发 · 性能改进
允许插入操作也触发自动清理中的清理活动,而不再仅由更新和删除触发(Laurenz Albe,Darafei Praliaskouski)§
以前,仅有插入活动时会触发自动分析,但不会触发自动清理,理由是不存在需要移除的死元组。然而,清理扫描还有其他有益的副作用,例如设置页面全可见位,从而提高仅索引扫描的效率。另外,让仅插入的表接受周期性清理,有助于分散“冻结”旧元组的工作量,避免整个表同时达到防回卷阈值时,突然需要执行大量冻结工作。
如有需要,可以通过新参数autovacuum_vacuum_insert_threshold和autovacuum_vacuum_insert_scale_factor,或等价的表存储选项来调整此行为。
原始发布条目 ·
13.0/changes/021增加maintenance_io_concurrency参数,以控制维护操作的 I/O 并发度 · 性能改进
增加maintenance_io_concurrency参数,以控制维护操作的 I/O 并发度(Thomas Munro)§
原始发布条目 ·
13.0/changes/022如果wal_level为 minimal,则允许在创建或重写关系的事务期间跳过 WAL 写入 · 性能改进
如果wal_level为
minimal,则允许在创建或重写关系的事务期间跳过 WAL 写入(Kyotaro Horiguchi)§对于大于wal_skip_threshold的关系,会对其文件执行 fsync,而不生成 WAL。以前,只有
COPY操作会这样处理,但其实现有一个缺陷,可能在崩溃恢复期间导致数据丢失。原始发布条目 ·
13.0/changes/023提高使用大量表空间时重放 DROP DATABASE 命令的性能 · 性能改进
提高使用大量表空间时重放
DROP DATABASE命令的性能(Fujii Masao)§原始发布条目 ·
13.0/changes/024允许 EXPLAIN、auto_explain、自动清理和pg_stat_statements跟踪 WAL 使用统计信息 · 新功能
允许
EXPLAIN、auto_explain、自动清理和pg_stat_statements跟踪 WAL 使用统计信息(Kirill Bychik,Julien Rouhaud)§ § §原始发布条目 ·
13.0/changes/030允许抽样记录 SQL 语句,而不必记录全部语句 · 新功能
允许抽样记录 SQL 语句,而不必记录全部语句(Adrien Nayrat)§
对于耗时超过log_min_duration_sample的语句,将按log_statement_sample_rate指定的比例记录日志。
原始发布条目 ·
13.0/changes/031将后端类型添加到 csvlog 日志输出中,并允许选择将其加入log_line_prefix日志输出 · 新功能
将后端类型添加到 csvlog 日志输出中,并允许选择将其加入log_line_prefix日志输出(Peter Eisentraut)§
原始发布条目 ·
13.0/changes/032改进对预备语句参数日志记录的控制 · 新功能
改进对预备语句参数日志记录的控制(Alexey Bashtanov,Álvaro Herrera)§ §
GUC 设置log_parameter_max_length控制记录未出错语句时输出的参数值的最大长度,而log_parameter_max_length_on_error对出错语句的日志执行相同控制。以前,发生错误时从不记录预备语句的参数。
原始发布条目 ·
13.0/changes/033允许在出错后记录函数调用回溯 · 新功能
允许在出错后记录函数调用回溯(Peter Eisentraut,Álvaro Herrera)§ §
新参数backtrace_functions指定哪些 C 函数应在出错时生成回溯。
原始发布条目 ·
13.0/changes/034向pg_stat_activity添加 leader_pid,以报告并行工作进程的领导者进程 · 新功能
向pg_stat_activity添加
leader_pid,以报告并行工作进程的领导者进程(Julien Rouhaud)§原始发布条目 ·
13.0/changes/036增加系统视图 pg_stat_progress_basebackup,以报告流式基础备份的进度 · 新功能
增加系统视图
pg_stat_progress_basebackup,以报告流式基础备份的进度(Fujii Masao)§原始发布条目 ·
13.0/changes/037增加系统视图 pg_stat_progress_analyze,以报告 ANALYZE 进度 · 新功能
增加系统视图
pg_stat_progress_analyze,以报告 ANALYZE 进度(Álvaro Herrera,Tatsuro Yamada,Vinayak Pokale)§原始发布条目 ·
13.0/changes/038增加系统视图 pg_shmem_allocations,以显示共享内存使用情况 · 新功能
增加系统视图
pg_shmem_allocations,以显示共享内存使用情况(Andres Freund,Robert Haas)§原始发布条目 ·
13.0/changes/039增加系统视图 pg_stat_slru,以监控内部 SLRU 缓存 · 新功能
增加系统视图
pg_stat_slru,以监控内部 SLRU 缓存(Tomas Vondra)§原始发布条目 ·
13.0/changes/040允许将track_activity_query_size设置为最高 1MB · 新功能
允许将track_activity_query_size设置为最高 1MB(Vyacheslav Makarov)§
以前的最大值为 100kB。
原始发布条目 ·
13.0/changes/041只允许超级用户查看ssl_passphrase_command设置 · 新功能
只允许超级用户查看ssl_passphrase_command设置(Insung Moon)§
此项修改出于安全考虑。
原始发布条目 ·
13.0/changes/047将服务器加密连接默认允许的最低 TLS 版本从 1.0 改为 1.2 · 新功能
将服务器加密连接默认允许的最低 TLS 版本从 1.0 改为 1.2(Peter Eisentraut)§
可以通过ssl_min_protocol_version控制这一选择。
原始发布条目 ·
13.0/changes/048允许在服务器启动后修改allow_system_table_mods · 新功能
允许在服务器启动后修改allow_system_table_mods(Peter Eisentraut)§
原始发布条目 ·
13.0/changes/050在设置allow_system_table_mods时,禁止非超级用户修改系统表 · 新功能
在设置allow_system_table_mods时,禁止非超级用户修改系统表(Peter Eisentraut)§
以前,如果在服务器启动时设置了allow_system_table_mods,非超级用户就可以对系统表执行
INSERT/UPDATE/DELETE命令。原始发布条目 ·
13.0/changes/051允许通过重载更改流复制配置设置 · 新功能
允许通过重载更改流复制配置设置(Sergei Kornilov)§
以前,更改primary_conninfo和primary_slot_name需要重启服务器。
原始发布条目 ·
13.0/changes/053允许 WAL 接收进程在未指定永久复制槽时使用临时复制槽 · 新功能
允许 WAL 接收进程在未指定永久复制槽时使用临时复制槽(Peter Eisentraut,Sergei Kornilov)§ §
可以使用wal_receiver_create_temp_slot启用此行为。
原始发布条目 ·
13.0/changes/054允许通过max_slot_wal_keep_size限制复制槽的 WAL 存储量 · 新功能
允许通过max_slot_wal_keep_size限制复制槽的 WAL 存储量(Kyotaro Horiguchi)§
需要超过此值的复制槽会被标记为无效。
原始发布条目 ·
13.0/changes/055允许在 WAL 引用无效页面时仍继续恢复 · 新功能
允许在 WAL 引用无效页面时仍继续恢复(Fujii Masao)§
可以使用ignore_invalid_pages启用此功能。
原始发布条目 ·
13.0/changes/059允许 FETCH FIRST 使用 WITH TIES 返回与最后一个结果行的排序值相同的所有额外行 · 新功能
允许
FETCH FIRST使用WITH TIES返回与最后一个结果行的排序值相同的所有额外行(Surafel Temesgen)§原始发布条目 ·
13.0/changes/061使 CREATE TABLE LIKE 将 CHECK 约束的 NO INHERIT 属性传递给所创建的表 · 新功能
使
CREATE TABLE LIKE将CHECK约束的NO INHERIT属性传递给所创建的表(Ildar Musin,Chris Travers)§原始发布条目 ·
13.0/changes/063对分区表使用 LOCK TABLE 时,不检查子表上的权限 · 新功能
对分区表使用
LOCK TABLE时,不检查子表上的权限(Amit Langote)§原始发布条目 ·
13.0/changes/064允许向标识列插入时使用 OVERRIDING USER VALUE · 新功能
允许向标识列插入时使用
OVERRIDING USER VALUE(Dean Rasheed)§原始发布条目 ·
13.0/changes/065增加 ALTER TABLE ... DROP EXPRESSION,以允许移除列的 GENERATED 属性 · 新功能
增加
ALTER TABLE ... DROP EXPRESSION,以允许移除列的GENERATED属性(Peter Eisentraut)§原始发布条目 ·
13.0/changes/066增加用于重命名视图列的 ALTER VIEW 语法 · 新功能
增加用于重命名视图列的
ALTER VIEW语法(Fujii Masao)§以前已经可以重命名视图列,但必须写成
ALTER TABLE RENAME COLUMN,这令人困惑。原始发布条目 ·
13.0/changes/068增加 ALTER TYPE 选项,以修改基础类型的 TOAST 属性和支持函数 · 新功能
增加
ALTER TYPE选项,以修改基础类型的 TOAST 属性和支持函数(Tomas Vondra,Tom Lane)§原始发布条目 ·
13.0/changes/069增加 CREATE DATABASE 的 LOCALE 选项 · 新功能
增加
CREATE DATABASE的LOCALE选项(Peter Eisentraut)§这将现有的
LC_COLLATE和LC_CTYPE选项合并为单个选项。原始发布条目 ·
13.0/changes/070允许 DROP DATABASE 断开正在使用目标数据库的会话,以使删除成功 · 新功能
允许
DROP DATABASE断开正在使用目标数据库的会话,以使删除成功(Pavel Stehule,Amit Kapila)§这通过
FORCE选项启用。原始发布条目 ·
13.0/changes/071增加结构成员 tg_updatedcols,使 C 语言更新触发器能够知道哪些列被更新 · 新功能
增加结构成员
tg_updatedcols,使 C 语言更新触发器能够知道哪些列被更新(Peter Eisentraut)§原始发布条目 ·
13.0/changes/072增加多态数据类型,供要求参数类型兼容的函数使用 · 新功能
增加多态数据类型,供要求参数类型兼容的函数使用(Pavel Stehule)§
新增数据类型为
anycompatible、anycompatiblearray、anycompatiblenonarray和anycompatiblerange。原始发布条目 ·
13.0/changes/073增加数据类型 regcollation 及相关函数,以表示排序规则对象的 OID · 新功能
增加数据类型
regcollation及相关函数,以表示排序规则对象的 OID(Julien Rouhaud)§原始发布条目 ·
13.0/changes/075增加 jsonb_set() 的另一个版本,改进对 NULL 的处理 · 新功能
增加
jsonb_set()的另一个版本,改进对NULL的处理(Andrew Dunstan)§新函数
jsonb_set_lax()根据请求处理值为NULL的新值:将指定键设为 JSON null、删除该键、抛出异常,或返回未经修改的jsonb值。原始发布条目 ·
13.0/changes/079增加 jsonpath 的 .datetime() 方法 · 新功能
增加 jsonpath 的 .
datetime()方法(Nikita Glukhov,Teodor Sigaev,Oleg Bartunov,Alexander Korotkov)§此函数允许将 JSON 值转换为时间戳,随后即可在
jsonpath表达式中处理这些时间戳。此项修改还增加了支持时区感知输出的jsonpath函数。原始发布条目 ·
13.0/changes/080增加 SQL 函数 NORMALIZE(),以规范化 Unicode 字符串,并增加 IS NORMALIZED 来检查是否已规范化 · 新功能
增加 SQL 函数
NORMALIZE(),以规范化 Unicode 字符串,并增加IS NORMALIZED来检查是否已规范化(Peter Eisentraut)§原始发布条目 ·
13.0/changes/081允许Unicode 转义,例如 E'\unnnn' 或 U&'\nnnn',指定数据库编码中可用的任何字符,即使数据库编码不是 UTF-8 · 新功能
允许Unicode 转义,例如
E'\u或nnnn'U&'\,指定数据库编码中可用的任何字符,即使数据库编码不是 UTF-8(Tom Lane)§nnnn'原始发布条目 ·
13.0/changes/083增加函数 gen_random_uuid(),以生成版本 4 UUID · 新功能
增加函数
gen_random_uuid(),以生成版本 4 UUID(Peter Eisentraut)§原始发布条目 ·
13.0/changes/087增加函数 min_scale(),返回完整精确表示 numeric 值所需的小数点右侧位数 · 新功能
增加函数
min_scale(),返回完整精确表示numeric值所需的小数点右侧位数(Pavel Stehule)§原始发布条目 ·
13.0/changes/090增加函数 trim_scale(),通过移除尾随零来减少 numeric 值的小数位数 · 新功能
增加函数
trim_scale(),通过移除尾随零来减少numeric值的小数位数(Pavel Stehule)§原始发布条目 ·
13.0/changes/091允许 libpq 客户端要求加密连接使用通道绑定 · 新功能
允许 libpq 客户端要求加密连接使用通道绑定(Jeff Davis)§
使用 libpq 连接参数
channel_binding,会强制 TLS 连接的另一端证明它知道用户的密码。这可以防止中间人攻击。原始发布条目 ·
13.0/changes/099增加 libpq 连接参数,以控制加密连接允许的最低和最高 TLS 版本 · 新功能
增加 libpq 连接参数,以控制加密连接允许的最低和最高 TLS 版本(Daniel Gustafsson)§ § §
这些设置为ssl_min_protocol_version和ssl_max_protocol_version。默认最低 TLS 版本为 1.2(这与以前的发行版相比是行为上的变化)。
原始发布条目 ·
13.0/changes/100允许使用密码解锁客户端证书 · 新功能
允许使用密码解锁客户端证书(Craig Ringer,Andrew Dunstan)§
这通过 libpq 的sslpassword连接参数启用。
原始发布条目 ·
13.0/changes/101为基础备份生成备份清单,并验证备份 · 新功能
为基础备份生成备份清单,并验证备份(Robert Haas)§ §
新工具pg_verifybackup可以验证备份。
原始发布条目 ·
13.0/changes/117使pg_basebackup默认估计备份总大小 · 新功能
使pg_basebackup默认估计备份总大小(Fujii Masao)§
这一计算使
pg_stat_progress_basebackup能够显示进度。如果不需要,可以使用--no-estimate-size选项禁用它。以前,只有使用--progress选项时才会进行这一计算。原始发布条目 ·
13.0/changes/118为pg_rewind增加配置备库的选项 · 新功能
为pg_rewind增加配置备库的选项(Paul Guo,Jimmy Yih,Ashwin Agrawal)§
这与pg_basebackup的
--write-recovery-conf选项一致。原始发布条目 ·
13.0/changes/119允许 pg_rewind 使用目标集群的restore_command获取所需的 WAL · 新功能
允许 pg_rewind 使用目标集群的restore_command获取所需的 WAL(Alexey Kondratov)§
这通过
-c/--restore-target-wal选项启用。原始发布条目 ·
13.0/changes/120增加 pg_waldump 报告的 PREPARE TRANSACTION 相关信息 · 新功能
增加 pg_waldump 报告的
PREPARE TRANSACTION相关信息(Fujii Masao)§原始发布条目 ·
13.0/changes/122增加pg_waldump选项 --quiet,以抑制非错误输出 · 新功能
增加pg_waldump选项
--quiet,以抑制非错误输出(Andres Freund,Robert Haas)§原始发布条目 ·
13.0/changes/123从 createuser 中移除 --adduser 和 --no-adduser · 新功能
从 createuser 中移除
--adduser和--no-adduser(Alexander Lakhin)§长期以来,用于此目的的推荐选项是
--superuser和--no-superuser。原始发布条目 ·
13.0/changes/128运行 pg_upgrade 时,将pg_upgrade程序所在的目录用作默认的 --new-bindir 设置 · 新功能
运行 pg_upgrade 时,将pg_upgrade程序所在的目录用作默认的
--new-bindir设置(Daniel Gustafsson)§原始发布条目 ·
13.0/changes/129更新全文检索使用的 Snowball 词干分析器词典 · 新功能
更新全文检索使用的 Snowball 词干分析器词典(Panagiotis Mavrogiorgos)§
这增加了希腊语词干提取,并改进了丹麦语和法语的词干提取。
原始发布条目 ·
13.0/changes/136允许非超级用户不使用密码就连接到postgres_fdw外部服务器 · 新功能
允许非超级用户不使用密码就连接到postgres_fdw外部服务器(Craig Ringer)§
具体来说,允许超级用户将某个用户映射的
password_required设置为 false。仍须注意防止非超级用户使用超级用户凭据连接到外部服务器。原始发布条目 ·
13.0/changes/152增加扩展bool_plperl,以在 SQL 布尔值和 PL/Perl 布尔值之间进行双向转换 · 新功能
增加扩展bool_plperl,以在 SQL 布尔值和 PL/Perl 布尔值之间进行双向转换(Ivan Panchenko)§
原始发布条目 ·
13.0/changes/155使pg_stat_statements将 SELECT ... FOR UPDATE 命令与不带 FOR UPDATE 的命令分别处理 · 新功能
使pg_stat_statements将
SELECT ... FOR UPDATE命令与不带FOR UPDATE的命令分别处理(Andrew Gierth,Vik Fearing)§原始发布条目 ·
13.0/changes/156增加pageinspect函数,以人类可读的格式输出 t_infomask/t_infomask2 值 · 新功能
增加pageinspect函数,以人类可读的格式输出
t_infomask/t_infomask2值(Craig Ringer,Sawada Masahiko,Michael Paquier)§ §原始发布条目 ·
13.0/changes/162
安全证据
共 37 条记录,来自官方安全矩阵及发布说明的提及。只有安全快照明确列出此分支时才显示修复版本;仅有提及不能确定漏洞适用性或新修复。
CVE-2025-8715 · PostgreSQL pg_dump newline in object name executes arbitrary code in psql client and in restore target server · CVSS 8.8
Improper neutralization of newlines in pg_dump in PostgreSQL allows a user of the origin server to inject arbitrary code for restore-time execution as the client operating system account running psql to restore the dump, via psql meta-commands inside a purpose-crafted object name. The same attacks can achieve SQL injection as a superuser of the restore target server. pg_dumpall, pg_restore, and pg_upgrade are also affected. Versions before PostgreSQL 17.6, 16.10, 15.14, 14.19, and 13.22 are affected. Versions before 11.20 are unaffected. CVE-2012-0868 had fixed this class of problem, but version 11.20 reintroduced it.
以上保留官方英文漏洞说明。
本分支修复于:13.22。组件:core server。
官方受影响分支记录:13。
AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
发布说明中的提及:
CVE-2025-8714 · PostgreSQL pg_dump lets superuser of origin server execute arbitrary code in psql client · CVSS 8.8
Untrusted data inclusion in pg_dump in PostgreSQL allows a malicious superuser of the origin server to inject arbitrary code for restore-time execution as the client operating system account running psql to restore the dump, via psql meta-commands. pg_dumpall is also affected. pg_restore is affected when used to generate a plain-format dump. This is similar to MySQL CVE-2024-21096. Versions before PostgreSQL 17.6, 16.10, 15.14, 14.19, and 13.22 are affected.
以上保留官方英文漏洞说明。
本分支修复于:13.22。组件:core server。
官方受影响分支记录:13。
AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
发布说明中的提及:
CVE-2025-8713 · PostgreSQL optimizer statistics can expose sampled data within a view, partition, or child table · CVSS 3.1
PostgreSQL optimizer statistics allow a user to read sampled data within a view that the user cannot access. Separately, statistics allow a user to read sampled data that a row security policy intended to hide. PostgreSQL maintains statistics for tables by sampling data available in columns; this data is consulted during the query planning process. Prior to this release, a user could craft a leaky operator that bypassed view access control lists (ACLs) and bypassed row security policies in partitioning or table inheritance hierarchies. Reachable statistics data notably included histograms and most-common-values lists. CVE-2017-7484 and CVE-2019-10130 intended to close this class of vulnerability, but this gap remained. Versions before PostgreSQL 17.6, 16.10, 15.14, 14.19, and 13.22 are affected.
以上保留官方英文漏洞说明。
本分支修复于:13.22。组件:core server。
官方受影响分支记录:13。
AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N
发布说明中的提及:
CVE-2025-4207 · PostgreSQL GB18030 encoding validation can read one byte past end of allocation for text that fails validation · CVSS 5.9
Buffer over-read in PostgreSQL GB18030 encoding validation allows a database input provider to achieve temporary denial of service on platforms where a 1-byte over-read can elicit process termination. This affects the database server and also libpq. Versions before PostgreSQL 17.5, 16.9, 15.13, 14.18, and 13.21 are affected.
以上保留官方英文漏洞说明。
本分支修复于:13.21。组件:core server。
官方受影响分支记录:13。
AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
发布说明中的提及:
CVE-2025-12818 · PostgreSQL libpq undersizes allocations, via integer wraparound · CVSS 5.9
Integer wraparound in multiple PostgreSQL libpq client library functions allows an application input provider or network peer to cause libpq to undersize an allocation and write out-of-bounds by hundreds of megabytes. This results in a segmentation fault for the application using libpq. Versions before PostgreSQL 18.1, 17.7, 16.11, 15.15, 14.20, and 13.23 are affected.
以上保留官方英文漏洞说明。
本分支修复于:13.23。组件:core server。
官方受影响分支记录:13。
AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
发布说明中的提及:
CVE-2025-12817 · PostgreSQL CREATE STATISTICS does not check for schema CREATE privilege · CVSS 3.1
Missing authorization in PostgreSQL CREATE STATISTICS command allows a table owner to achieve denial of service against other CREATE STATISTICS users by creating in any schema. A later CREATE STATISTICS for the same name, from a user having the CREATE privilege, would then fail. Versions before PostgreSQL 18.1, 17.7, 16.11, 15.15, 14.20, and 13.23 are affected.
以上保留官方英文漏洞说明。
本分支修复于:13.23。组件:core server。
官方受影响分支记录:13。
AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:L
发布说明中的提及:
CVE-2025-1094 · PostgreSQL quoting APIs miss neutralizing quoting syntax in text that fails encoding validation · CVSS 8.1
Improper neutralization of quoting syntax in PostgreSQL libpq functions PQescapeLiteral(), PQescapeIdentifier(), PQescapeString(), and PQescapeStringConn() allows a database input provider to achieve SQL injection in certain usage patterns. Specifically, SQL injection requires the application to use the function result to construct input to psql, the PostgreSQL interactive terminal. Similarly, improper neutralization of quoting syntax in PostgreSQL command line utility programs allows a source of command line arguments to achieve SQL injection when client_encoding is BIG5 and server_encoding is one of EUC_TW or MULE_INTERNAL. Versions before PostgreSQL 17.3, 16.7, 15.11, 14.16, and 13.19 are affected.
以上保留官方英文漏洞说明。
本分支修复于:13.19。组件:core server。
官方受影响分支记录:13。
AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
发布说明中的提及:
CVE-2024-7348 · PostgreSQL relation replacement during pg_dump executes arbitrary SQL · CVSS 8.8
Time-of-check Time-of-use (TOCTOU) race condition in pg_dump in PostgreSQL allows an object creator to execute arbitrary SQL functions as the user running pg_dump, which is often a superuser. The attack involves replacing another relation type with a view or foreign table. The attack requires waiting for pg_dump to start, but winning the race condition is trivial if the attacker retains an open transaction. Versions before PostgreSQL 16.4, 15.8, 14.13, 13.16, and 12.20 are affected. The PostgreSQL project thanks Noah Misch for reporting this problem.
以上保留官方英文漏洞说明。
本分支修复于:13.16。组件:core server。
官方受影响分支记录:13。
AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
发布说明中的提及:
CVE-2024-10979 · PostgreSQL PL/Perl environment variable changes execute arbitrary code · CVSS 8.8
Incorrect control of environment variables in PostgreSQL PL/Perl allows an unprivileged database user to change sensitive process environment variables (e.g. PATH ). That often suffices to enable arbitrary code execution, even if the attacker lacks a database server operating system user. Versions before PostgreSQL 17.1, 16.5, 15.9, 14.14, 13.17, and 12.21 are affected. The PostgreSQL project thanks Coby Abrams for reporting this problem.
以上保留官方英文漏洞说明。
本分支修复于:13.17。组件:core server。
官方受影响分支记录:13。
AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
发布说明中的提及:
CVE-2024-10978 · PostgreSQL SET ROLE, SET SESSION AUTHORIZATION reset to wrong user ID · CVSS 4.2
Incorrect privilege assignment in PostgreSQL allows a less-privileged application user to view or change different rows from those intended. An attack requires the application to use SET ROLE , SET SESSION AUTHORIZATION , or an equivalent feature. The problem arises when an application query uses parameters from the attacker or conveys query results to the attacker. If that query reacts to current_setting('role') or the current user ID, it may modify or return data as though the session had not used SET ROLE or SET SESSION AUTHORIZATION . The attacker does not control which incorrect user ID applies. Query text from less-privileged sources is not a concern here, because SET ROLE and SET SESSION AUTHORIZATION are not sandboxes for unvetted queries. Versions before PostgreSQL 17.1, 16.5, 15.9, 14.14, 13.17, and 12.21 are affected. The PostgreSQL project thanks Tom Lane for reporting this problem.
以上保留官方英文漏洞说明。
本分支修复于:13.17。组件:core server。
官方受影响分支记录:13。
AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N
发布说明中的提及:
CVE-2024-10977 · PostgreSQL libpq retains an error message from man-in-the-middle · CVSS 3.1
Client use of server error message in PostgreSQL allows a server not trusted under current SSL or GSS settings to furnish arbitrary non-NUL bytes to the libpq application. For example, a man-in-the-middle attacker could send a long error message that a human or screen-scraper user of psql mistakes for valid query results. This is probably not a concern for clients where the user interface unambiguously indicates the boundary between one error message and other text. Versions before PostgreSQL 17.1, 16.5, 15.9, 14.14, 13.17, and 12.21 are affected. The PostgreSQL project thanks Jacob Champion for reporting this problem.
以上保留官方英文漏洞说明。
本分支修复于:13.17。组件:client。
官方受影响分支记录:13。
AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:N
发布说明中的提及:
CVE-2024-10976 · PostgreSQL row security below e.g. subqueries disregards user ID changes · CVSS 4.2
Incomplete tracking in PostgreSQL of tables with row security allows a reused query to view or change different rows from those intended. CVE-2023-2455 and CVE-2016-2193 fixed most interaction between row security and user ID changes. They missed cases where a subquery, WITH query, security invoker view, or SQL-language function references a table with a row-level security policy. This has the same consequences as the two earlier CVEs. That is to say, it leads to potentially incorrect policies being applied in cases where role-specific policies are used and a given query is planned under one role and then executed under other roles. This scenario can happen under security definer functions or when a common user and query is planned initially and then re-used across multiple SET ROLEs. Applying an incorrect policy may permit a user to complete otherwise-forbidden reads and modifications. This affects only databases that have used CREATE POLICY to define a row security policy. An attacker must tailor an attack to a particular application's pattern of query plan reuse, user ID changes, and role-specific row security policies. Versions before PostgreSQL 17.1, 16.5, 15.9, 14.14, 13.17, and 12.21 are affected.
以上保留官方英文漏洞说明。
本分支修复于:13.17。组件:core server。
官方受影响分支记录:13。
AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N
发布说明中的提及:
CVE-2024-0985 · PostgreSQL non-owner REFRESH MATERIALIZED VIEW CONCURRENTLY executes arbitrary SQL · CVSS 8.0
UPDATE (June 19, 2024) : Added v16 as impacted. Updated description to clarify the attack vector. Late privilege drop in REFRESH MATERIALIZED VIEW CONCURRENTLY in PostgreSQL allows an object creator to execute arbitrary SQL functions as the command issuer. The command intends to run SQL functions as the owner of the materialized view, enabling safe refresh of untrusted materialized views. The victim is a superuser or member of one of the attacker's roles. The attack requires luring the victim into running REFRESH MATERIALIZED VIEW CONCURRENTLY on the attacker's materialized view.
以上保留官方英文漏洞说明。
本分支修复于:13.14。组件:core server。
官方受影响分支记录:13。
AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H
发布说明中的提及:
CVE-2023-5870 · Role "pg_signal_backend" can signal certain superuser processes · CVSS 2.2
Documentation says the pg_signal_backend role cannot signal "a backend owned by a superuser". On the contrary, it can signal background workers, including the logical replication launcher. It can signal autovacuum workers and the autovacuum launcher. Signaling autovacuum workers and those two launchers provides no meaningful exploit, so exploiting this vulnerability requires a non-core extension with a less-resilient background worker. For example, a non-core background worker that does not auto-restart would experience a denial of service with respect to that particular background worker. The PostgreSQL project thanks Hemanth Sandrana and Mahendrakar Srinivasarao for reporting this problem.
以上保留官方英文漏洞说明。
本分支修复于:13.13。组件:core server。
官方受影响分支记录:13。
AV:N/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:L
发布说明中的提及:
CVE-2023-5869 · Buffer overrun from integer overflow in array modification · CVSS 8.8
While modifying certain SQL array values, missing overflow checks let authenticated database users write arbitrary bytes to a memory area that facilitates arbitrary code execution. Missing overflow checks also let authenticated database users read a wide area of server memory. The CVE-2021-32027 fix covered some attacks of this description, but it missed others. The PostgreSQL project thanks Pedro Gallegos for reporting this problem.
以上保留官方英文漏洞说明。
本分支修复于:13.13。组件:core server。
官方受影响分支记录:13。
AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
发布说明中的提及:
CVE-2023-5868 · Memory disclosure in aggregate function calls · CVSS 4.3
Certain aggregate function calls receiving "unknown"-type arguments could disclose bytes of server memory from the end of the "unknown"-type value to the next zero byte. One typically gets an "unknown"-type value via a string literal having no type designation. We have not confirmed or ruled out viability of attacks that arrange for presence of notable, confidential information in disclosed bytes. The PostgreSQL project thanks Jingzhou Fu for reporting this problem.
以上保留官方英文漏洞说明。
本分支修复于:13.13。组件:core server。
官方受影响分支记录:13。
AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
发布说明中的提及:
CVE-2023-39417 · Extension script @substitutions@ within quoting allow SQL injection · CVSS 7.5
An extension script is vulnerable if it uses @extowner@ , @extschema@ , or @extschema:...@ inside a quoting construct (dollar quoting, '' , or "" ). No bundled extension is vulnerable. Vulnerable uses do appear in a documentation example and in non-bundled extensions. Hence, the attack prerequisite is an administrator having installed files of a vulnerable, trusted, non-bundled extension. Subject to that prerequisite, this enables an attacker having database-level CREATE privilege to execute arbitrary code as the bootstrap superuser. PostgreSQL will block this attack in the core server, so there's no need to modify individual extensions. The PostgreSQL project thanks Micah Gates, Valerie Woolard, Tim Carey-Smith, and Christoph Berg for reporting this problem.
以上保留官方英文漏洞说明。
本分支修复于:13.12。组件:core server。
官方受影响分支记录:13。
AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
发布说明中的提及:
CVE-2023-2455 · Row security policies disregard user ID changes after inlining · CVSS 4.2
While CVE-2016-2193 fixed most interaction between row security and user ID changes, it missed a scenario involving function inlining. This leads to potentially incorrect policies being applied in cases where role-specific policies are used and a given query is planned under one role and then executed under other roles. This scenario can happen under security definer functions or when a common user and query is planned initially and then re-used across multiple SET ROLE s. Applying an incorrect policy may permit a user to complete otherwise-forbidden reads and modifications. This affects only databases that have used CREATE POLICY to define a row security policy. The PostgreSQL project thanks Wolfgang Walther for reporting this problem.
以上保留官方英文漏洞说明。
本分支修复于:13.11。组件:core server。
官方受影响分支记录:13。
AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N
发布说明中的提及:
CVE-2023-2454 · CREATE SCHEMA ... schema_element defeats protective search_path changes · CVSS 7.2
This enabled an attacker having database-level CREATE privilege to execute arbitrary code as the bootstrap superuser. Database owners have that right by default, and explicit grants may extend it to other users. The PostgreSQL project thanks Alexander Lakhin for reporting this problem.
以上保留官方英文漏洞说明。
本分支修复于:13.11。组件:core server。
官方受影响分支记录:13。
AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
发布说明中的提及:
CVE-2022-41862 · Client memory disclosure when connecting, with Kerberos, to modified server · CVSS 3.7
A modified, unauthenticated server can send an unterminated string during the establishment of Kerberos transport encryption. When a libpq client application has a Kerberos credential cache and doesn't explicitly disable option gssencmode , a server can cause libpq to over-read and report an error message containing uninitialized bytes from and following its receive buffer. If libpq's caller somehow makes that message accessible to the attacker, this achieves a disclosure of the over-read bytes. We have not confirmed or ruled out viability of attacks that arrange for a crash or for presence of notable, confidential information in disclosed bytes. The PostgreSQL project thanks Jacob Champion for reporting this problem.
以上保留官方英文漏洞说明。
本分支修复于:13.10。组件:client。
官方受影响分支记录:13。
AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N
发布说明中的提及:
CVE-2022-2625 · Extension scripts replace objects not belonging to the extension · CVSS 7.1
Some extensions use CREATE OR REPLACE or CREATE IF NOT EXISTS commands. Some don't adhere to the documented rule to target only objects known to be extension members already. An attack requires permission to create non-temporary objects in at least one schema, ability to lure or wait for an administrator to create or update an affected extension in that schema, and ability to lure or wait for a victim to use the object targeted in CREATE OR REPLACE or CREATE IF NOT EXISTS . Given all three prerequisites, the attacker can run arbitrary code as the victim role, which may be a superuser. Known-affected extensions include both PostgreSQL-bundled and non-bundled extensions. PostgreSQL is blocking this attack in the core server, so there's no need to modify individual extensions. The PostgreSQL project thanks Sven Klemm for reporting this problem.
以上保留官方英文漏洞说明。
本分支修复于:13.8。组件:core server。
官方受影响分支记录:13。
AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H
发布说明中的提及:
CVE-2022-1552 · Autovacuum, REINDEX, and others omit "security restricted operation" sandbox · CVSS 8.8
Autovacuum, REINDEX , CREATE INDEX , REFRESH MATERIALIZED VIEW , CLUSTER , and pg_amcheck made incomplete efforts to operate safely when a privileged user is maintaining another user's objects. Those commands activated relevant protections too late or not at all. An attacker having permission to create non-temp objects in at least one schema could execute arbitrary SQL functions under a superuser identity. While promptly updating PostgreSQL is the best remediation for most users, a user unable to do that can work around the vulnerability by disabling autovacuum, not manually running the above commands, and not restoring from output of the pg_dump command. Performance may degrade quickly under this workaround. VACUUM is safe, and all commands are fine when a trusted user owns the target object. The PostgreSQL project thanks Alexander Lakhin for reporting this problem.
以上保留官方英文漏洞说明。
本分支修复于:13.7。组件:core server。
官方受影响分支记录:13。
AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
发布说明中的提及:
CVE-2021-3677 · Memory disclosure in certain queries · CVSS 6.5
A purpose-crafted query can read arbitrary bytes of server memory. In the default configuration, any authenticated database user can complete this attack at will. The attack does not require the ability to create objects. If server settings include max_worker_processes=0 , the known versions of this attack are infeasible. However, undiscovered variants of the attack may be independent of that setting.
以上保留官方英文漏洞说明。
本分支修复于:13.4。组件:core server。
官方受影响分支记录:13。
AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
发布说明中的提及:
CVE-2021-3449 · CVE-2021-3449
CVE-2021-3393 · Partition constraint violation errors leak values of denied columns · CVSS 3.1
A user having an UPDATE privilege on a partitioned table but lacking the SELECT privilege on some column may be able to acquire denied-column values from an error message. This is similar to CVE-2014-8161 , but the conditions to exploit are more rare. The PostgreSQL project thanks Heikki Linnakangas for reporting this problem.
以上保留官方英文漏洞说明。
本分支修复于:13.2。组件:core server。
官方受影响分支记录:13。
AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N
发布说明中的提及:
CVE-2021-32029 · Memory disclosure in partitioned-table UPDATE ... RETURNING · CVSS 6.5
Using an UPDATE ... RETURNING on a purpose-crafted partitioned table, an attacker can read arbitrary bytes of server memory. In the default configuration, any authenticated database user can create prerequisite objects and complete this attack at will. A user lacking the CREATE and TEMPORARY privileges on all databases and the CREATE privilege on all schemas typically cannot use this attack at will. The PostgreSQL project thanks Tom Lane for reporting this problem.
以上保留官方英文漏洞说明。
本分支修复于:13.3。组件:core server。
官方受影响分支记录:13。
AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
发布说明中的提及:
CVE-2021-32028 · Memory disclosure in INSERT ... ON CONFLICT ... DO UPDATE · CVSS 6.5
Using an INSERT ... ON CONFLICT ... DO UPDATE command on a purpose-crafted table, an attacker can read arbitrary bytes of server memory. In the default configuration, any authenticated database user can create prerequisite objects and complete this attack at will. A user lacking the CREATE and TEMPORARY privileges on all databases and the CREATE privilege on all schemas cannot use this attack at will. The PostgreSQL project thanks Andres Freund for reporting this problem.
以上保留官方英文漏洞说明。
本分支修复于:13.3。组件:core server。
官方受影响分支记录:13。
AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
发布说明中的提及:
CVE-2021-32027 · Buffer overrun from integer overflow in array subscripting calculations · CVSS 6.5
While modifying certain SQL array values, missing bounds checks let authenticated database users write arbitrary bytes to a wide area of server memory. The PostgreSQL project thanks Tom Lane for reporting this problem.
以上保留官方英文漏洞说明。
本分支修复于:13.3。组件:core server。
官方受影响分支记录:13。
AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
发布说明中的提及:
CVE-2021-23222 · libpq processes unencrypted bytes from man-in-the-middle · CVSS 3.7
A man-in-the-middle attacker can inject false responses to the client's first few queries, despite the use of SSL certificate verification and encryption. If more preconditions hold, the attacker can exfiltrate the client's password or other confidential data that might be transmitted early in a session. The attacker must have a way to trick the client's intended server into making the confidential data accessible to the attacker. A known implementation having that property is a PostgreSQL configuration vulnerable to CVE-2021-23214 . As with any exploitation of CVE-2021-23214 , the server must be using trust authentication with a clientcert requirement or using cert authentication. To disclose a password, the client must be in possession of a password, which is atypical when using an authentication configuration vulnerable to CVE-2021-23214 . The attacker must have some other way to access the server to retrieve the exfiltrated data (a valid, unprivileged login account would be sufficient). The PostgreSQL project thanks Jacob Champion for reporting this problem.
以上保留官方英文漏洞说明。
本分支修复于:13.5。组件:client。
官方受影响分支记录:13。
AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N
发布说明中的提及:
CVE-2021-23214 · Server processes unencrypted bytes from man-in-the-middle · CVSS 8.1
When the server is configured to use trust authentication with a clientcert requirement or to use cert authentication, a man-in-the-middle attacker can inject arbitrary SQL queries when a connection is first established, despite the use of SSL certificate verification and encryption. This is similar to CVE-2011-0411 (different product). The PostgreSQL project thanks Jacob Champion for reporting this problem.
以上保留官方英文漏洞说明。
本分支修复于:13.5。组件:core server。
官方受影响分支记录:13。
AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
发布说明中的提及:
CVE-2021-20229 · Single-column SELECT privilege enables reading all columns · CVSS 3.1
A user having a SELECT privilege on an individual column can craft a special query that returns all columns of the table. Additionally, a stored view that uses column-level privileges will have incomplete column-usage bitmaps. In installations that depend on column-level permissions for security, it is recommended to execute CREATE OR REPLACE on all user-defined views to force them to be re-parsed. The PostgreSQL project thanks Sven Klemm for reporting this problem.
以上保留官方英文漏洞说明。
本分支修复于:13.2。组件:core server。
官方受影响分支记录:13。
AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N
发布说明中的提及:
CVE-2020-25696 · psql's \gset allows overwriting specially treated variables · CVSS 7.5
The \gset meta-command, which sets psql variables based on query results, does not distinguish variables that control psql behavior. If an interactive psql session uses \gset when querying a compromised server, the attacker can execute arbitrary code as the operating system account running psql . Using \gset with a prefix not found among specially treated variables, e.g. any lowercase string, precludes the attack in an unpatched psql . The PostgreSQL project thanks Nick Cleaton for reporting this problem.
以上保留官方英文漏洞说明。
本分支修复于:13.1。组件:client。
官方受影响分支记录:13。
AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
发布说明中的提及:
CVE-2020-25695 · Multiple features escape "security restricted operation" sandbox · CVSS 8.8
An attacker having permission to create non-temporary objects in at least one schema can execute arbitrary SQL functions under the identity of a superuser. While promptly updating PostgreSQL is the best remediation for most users, a user unable to do that can work around the vulnerability by disabling autovacuum and not manually running ANALYZE , CLUSTER , REINDEX , CREATE INDEX , VACUUM FULL , REFRESH MATERIALIZED VIEW , or a restore from output of the pg_dump command. Performance may degrade quickly under this workaround. VACUUM without the FULL option is safe, and all commands are fine when a trusted user owns the target object. The PostgreSQL project thanks Etienne Stalmans for reporting this problem.
以上保留官方英文漏洞说明。
本分支修复于:13.1。组件:core server。
官方受影响分支记录:13。
AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
发布说明中的提及:
CVE-2020-25694 · Reconnection can downgrade connection security settings · CVSS 8.1
Many PostgreSQL-provided client applications have options that create additional database connections. Some of those applications reuse only the basic connection parameters (e.g. host , user , port ), dropping others. If this drops a security-relevant parameter (e.g. channel_binding , sslmode , requirepeer , gssencmode ), the attacker has an opportunity to complete a MITM attack or observe cleartext transmission. Affected applications are clusterdb , pg_dump , pg_restore , psql , reindexdb , and vacuumdb . The vulnerability arises only if one invokes an affected client application with a connection string containing a security-relevant parameter. This also fixes how the \connect command of psql reuses connection parameters, i.e. all non-overridden parameters from a previous connection string now re-used. The PostgreSQL project thanks Peter Eisentraut for reporting this problem.
以上保留官方英文漏洞说明。
本分支修复于:13.1。组件:client。
官方受影响分支记录:13。
AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
发布说明中的提及: