↑↓ 选择 ↵ 打开 ⌫ 改范围 完整检索页

pgsql.cc 提供对 postgresql.org 官网内容的中文翻译,由 Pigsty 团队维护。

百科 / 版本发布

PostgreSQL 13

已停止支持 · 记录构建 13.23 · 2025-11-13

此大版本已停止支持,相关记录用于查阅历史;没有更新的安全记录不代表仍可安全运行。

首次正式发布
2020-09-24
支持结束
2025-11-13
已收录发布版本
24
原始发布说明条目
1164

手册与来源

PostgreSQL 13 本站手册 · 已加载 1065 页。

手册加载时间:2026-09-27T00:10:45.258078。

发布说明快照:2026-09-26。安全证据快照:2026-09-26。PDF 链接按本地文件是否存在提供,历史版本的语言与 HTML 手册可能不同。生命周期参见官方版本政策。

升级注意事项

跨大版本升级需要导出/恢复或 pg_upgrade 等迁移方式,应阅读沿途大版本的发布说明与目标版本手册。小版本更新也可能要求额外操作,请核对对应发布的迁移说明。官方升级政策。

13.0 的兼容性变化 · 从首发到 13.23 的变化

13.0 的原始迁移说明

对于希望从任何先前版本迁移数据的用户,需要使用pg_dumpall进行导出/恢复,或使用pg_upgrade或逻辑复制。有关迁移到新主版本的一般信息,请参见第 18.6 节。

版本 13 包含许多可能影响与先前版本兼容性的变更。请注意以下不兼容性:

发布历史

每次发布的原始变更均独立保留。CVE 数量表示发布说明中的提及,可能包含后续纠正,不等于本次新修复漏洞数。

版本日期/快照截止时间全部变化BUG 修复迁移条目提及 CVE
13.23 2025-11-13 432202
13.22 2025-08-14 441005
13.21 2025-05-08 281201
13.20 2025-02-20 2101
13.19 2025-02-13 452601
13.18 2024-11-21 4201
13.17 2024-11-14 381404
13.16 2024-08-08 361702
13.15 2024-05-09 351500
13.14 2024-02-08 401501
13.13 2023-11-09 481703
13.12 2023-08-10 361701
13.11 2023-05-11 552802
13.10 2023-02-09 381501
13.9 2022-11-10 411900
13.8 2022-08-11 431802
13.7 2022-05-12 382001
13.6 2022-02-10 412100
13.5 2021-11-11 773602
13.4 2021-08-12 772803
13.3 2021-05-13 482703
13.2 2021-02-11 804202
13.1 2020-11-12 492403
13.0 2020-09-24 1784150

首次发布变化

13.0 的原始条目,包含功能和兼容性变化。类别用于浏览,不是上游原始分类。

匹配 178 / 178 条原始变更。

安全证据

共 37 条记录,来自官方安全矩阵及发布说明的提及。只有安全快照明确列出此分支时才显示修复版本;仅有提及不能确定漏洞适用性或新修复。

CVE-2025-8715 · PostgreSQL pg_dump newline in object name executes arbitrary code in psql client and in restore target server · CVSS 8.8

Improper neutralization of newlines in pg_dump in PostgreSQL allows a user of the origin server to inject arbitrary code for restore-time execution as the client operating system account running psql to restore the dump, via psql meta-commands inside a purpose-crafted object name. The same attacks can achieve SQL injection as a superuser of the restore target server. pg_dumpall, pg_restore, and pg_upgrade are also affected. Versions before PostgreSQL 17.6, 16.10, 15.14, 14.19, and 13.22 are affected. Versions before 11.20 are unaffected. CVE-2012-0868 had fixed this class of problem, but version 11.20 reintroduced it.

以上保留官方英文漏洞说明。

本分支修复于:13.22。组件:core server。

官方受影响分支记录:13。

AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

发布说明中的提及:

CVE-2025-8714 · PostgreSQL pg_dump lets superuser of origin server execute arbitrary code in psql client · CVSS 8.8

Untrusted data inclusion in pg_dump in PostgreSQL allows a malicious superuser of the origin server to inject arbitrary code for restore-time execution as the client operating system account running psql to restore the dump, via psql meta-commands. pg_dumpall is also affected. pg_restore is affected when used to generate a plain-format dump. This is similar to MySQL CVE-2024-21096. Versions before PostgreSQL 17.6, 16.10, 15.14, 14.19, and 13.22 are affected.

以上保留官方英文漏洞说明。

本分支修复于:13.22。组件:core server。

官方受影响分支记录:13。

AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

发布说明中的提及:

CVE-2025-8713 · PostgreSQL optimizer statistics can expose sampled data within a view, partition, or child table · CVSS 3.1

PostgreSQL optimizer statistics allow a user to read sampled data within a view that the user cannot access. Separately, statistics allow a user to read sampled data that a row security policy intended to hide. PostgreSQL maintains statistics for tables by sampling data available in columns; this data is consulted during the query planning process. Prior to this release, a user could craft a leaky operator that bypassed view access control lists (ACLs) and bypassed row security policies in partitioning or table inheritance hierarchies. Reachable statistics data notably included histograms and most-common-values lists. CVE-2017-7484 and CVE-2019-10130 intended to close this class of vulnerability, but this gap remained. Versions before PostgreSQL 17.6, 16.10, 15.14, 14.19, and 13.22 are affected.

以上保留官方英文漏洞说明。

本分支修复于:13.22。组件:core server。

官方受影响分支记录:13。

AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N

发布说明中的提及:

CVE-2025-4207 · PostgreSQL GB18030 encoding validation can read one byte past end of allocation for text that fails validation · CVSS 5.9

Buffer over-read in PostgreSQL GB18030 encoding validation allows a database input provider to achieve temporary denial of service on platforms where a 1-byte over-read can elicit process termination. This affects the database server and also libpq. Versions before PostgreSQL 17.5, 16.9, 15.13, 14.18, and 13.21 are affected.

以上保留官方英文漏洞说明。

本分支修复于:13.21。组件:core server。

官方受影响分支记录:13。

AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H

发布说明中的提及:

CVE-2025-12818 · PostgreSQL libpq undersizes allocations, via integer wraparound · CVSS 5.9

Integer wraparound in multiple PostgreSQL libpq client library functions allows an application input provider or network peer to cause libpq to undersize an allocation and write out-of-bounds by hundreds of megabytes. This results in a segmentation fault for the application using libpq. Versions before PostgreSQL 18.1, 17.7, 16.11, 15.15, 14.20, and 13.23 are affected.

以上保留官方英文漏洞说明。

本分支修复于:13.23。组件:core server。

官方受影响分支记录:13。

AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H

发布说明中的提及:

CVE-2025-12817 · PostgreSQL CREATE STATISTICS does not check for schema CREATE privilege · CVSS 3.1

Missing authorization in PostgreSQL CREATE STATISTICS command allows a table owner to achieve denial of service against other CREATE STATISTICS users by creating in any schema. A later CREATE STATISTICS for the same name, from a user having the CREATE privilege, would then fail. Versions before PostgreSQL 18.1, 17.7, 16.11, 15.15, 14.20, and 13.23 are affected.

以上保留官方英文漏洞说明。

本分支修复于:13.23。组件:core server。

官方受影响分支记录:13。

AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:L

发布说明中的提及:

CVE-2025-1094 · PostgreSQL quoting APIs miss neutralizing quoting syntax in text that fails encoding validation · CVSS 8.1

Improper neutralization of quoting syntax in PostgreSQL libpq functions PQescapeLiteral(), PQescapeIdentifier(), PQescapeString(), and PQescapeStringConn() allows a database input provider to achieve SQL injection in certain usage patterns. Specifically, SQL injection requires the application to use the function result to construct input to psql, the PostgreSQL interactive terminal. Similarly, improper neutralization of quoting syntax in PostgreSQL command line utility programs allows a source of command line arguments to achieve SQL injection when client_encoding is BIG5 and server_encoding is one of EUC_TW or MULE_INTERNAL. Versions before PostgreSQL 17.3, 16.7, 15.11, 14.16, and 13.19 are affected.

以上保留官方英文漏洞说明。

本分支修复于:13.19。组件:core server。

官方受影响分支记录:13。

AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

发布说明中的提及:

CVE-2024-7348 · PostgreSQL relation replacement during pg_dump executes arbitrary SQL · CVSS 8.8

Time-of-check Time-of-use (TOCTOU) race condition in pg_dump in PostgreSQL allows an object creator to execute arbitrary SQL functions as the user running pg_dump, which is often a superuser. The attack involves replacing another relation type with a view or foreign table. The attack requires waiting for pg_dump to start, but winning the race condition is trivial if the attacker retains an open transaction. Versions before PostgreSQL 16.4, 15.8, 14.13, 13.16, and 12.20 are affected. The PostgreSQL project thanks Noah Misch for reporting this problem.

以上保留官方英文漏洞说明。

本分支修复于:13.16。组件:core server。

官方受影响分支记录:13。

AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

发布说明中的提及:

CVE-2024-10979 · PostgreSQL PL/Perl environment variable changes execute arbitrary code · CVSS 8.8

Incorrect control of environment variables in PostgreSQL PL/Perl allows an unprivileged database user to change sensitive process environment variables (e.g. PATH ). That often suffices to enable arbitrary code execution, even if the attacker lacks a database server operating system user. Versions before PostgreSQL 17.1, 16.5, 15.9, 14.14, 13.17, and 12.21 are affected. The PostgreSQL project thanks Coby Abrams for reporting this problem.

以上保留官方英文漏洞说明。

本分支修复于:13.17。组件:core server。

官方受影响分支记录:13。

AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

发布说明中的提及:

CVE-2024-10978 · PostgreSQL SET ROLE, SET SESSION AUTHORIZATION reset to wrong user ID · CVSS 4.2

Incorrect privilege assignment in PostgreSQL allows a less-privileged application user to view or change different rows from those intended. An attack requires the application to use SET ROLE , SET SESSION AUTHORIZATION , or an equivalent feature. The problem arises when an application query uses parameters from the attacker or conveys query results to the attacker. If that query reacts to current_setting('role') or the current user ID, it may modify or return data as though the session had not used SET ROLE or SET SESSION AUTHORIZATION . The attacker does not control which incorrect user ID applies. Query text from less-privileged sources is not a concern here, because SET ROLE and SET SESSION AUTHORIZATION are not sandboxes for unvetted queries. Versions before PostgreSQL 17.1, 16.5, 15.9, 14.14, 13.17, and 12.21 are affected. The PostgreSQL project thanks Tom Lane for reporting this problem.

以上保留官方英文漏洞说明。

本分支修复于:13.17。组件:core server。

官方受影响分支记录:13。

AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N

发布说明中的提及:

CVE-2024-10977 · PostgreSQL libpq retains an error message from man-in-the-middle · CVSS 3.1

Client use of server error message in PostgreSQL allows a server not trusted under current SSL or GSS settings to furnish arbitrary non-NUL bytes to the libpq application. For example, a man-in-the-middle attacker could send a long error message that a human or screen-scraper user of psql mistakes for valid query results. This is probably not a concern for clients where the user interface unambiguously indicates the boundary between one error message and other text. Versions before PostgreSQL 17.1, 16.5, 15.9, 14.14, 13.17, and 12.21 are affected. The PostgreSQL project thanks Jacob Champion for reporting this problem.

以上保留官方英文漏洞说明。

本分支修复于:13.17。组件:client。

官方受影响分支记录:13。

AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:N

发布说明中的提及:

CVE-2024-10976 · PostgreSQL row security below e.g. subqueries disregards user ID changes · CVSS 4.2

Incomplete tracking in PostgreSQL of tables with row security allows a reused query to view or change different rows from those intended. CVE-2023-2455 and CVE-2016-2193 fixed most interaction between row security and user ID changes. They missed cases where a subquery, WITH query, security invoker view, or SQL-language function references a table with a row-level security policy. This has the same consequences as the two earlier CVEs. That is to say, it leads to potentially incorrect policies being applied in cases where role-specific policies are used and a given query is planned under one role and then executed under other roles. This scenario can happen under security definer functions or when a common user and query is planned initially and then re-used across multiple SET ROLEs. Applying an incorrect policy may permit a user to complete otherwise-forbidden reads and modifications. This affects only databases that have used CREATE POLICY to define a row security policy. An attacker must tailor an attack to a particular application's pattern of query plan reuse, user ID changes, and role-specific row security policies. Versions before PostgreSQL 17.1, 16.5, 15.9, 14.14, 13.17, and 12.21 are affected.

以上保留官方英文漏洞说明。

本分支修复于:13.17。组件:core server。

官方受影响分支记录:13。

AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N

发布说明中的提及:

CVE-2024-0985 · PostgreSQL non-owner REFRESH MATERIALIZED VIEW CONCURRENTLY executes arbitrary SQL · CVSS 8.0

UPDATE (June 19, 2024) : Added v16 as impacted. Updated description to clarify the attack vector. Late privilege drop in REFRESH MATERIALIZED VIEW CONCURRENTLY in PostgreSQL allows an object creator to execute arbitrary SQL functions as the command issuer. The command intends to run SQL functions as the owner of the materialized view, enabling safe refresh of untrusted materialized views. The victim is a superuser or member of one of the attacker's roles. The attack requires luring the victim into running REFRESH MATERIALIZED VIEW CONCURRENTLY on the attacker's materialized view.

以上保留官方英文漏洞说明。

本分支修复于:13.14。组件:core server。

官方受影响分支记录:13。

AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H

发布说明中的提及:

CVE-2023-5870 · Role "pg_signal_backend" can signal certain superuser processes · CVSS 2.2

Documentation says the pg_signal_backend role cannot signal "a backend owned by a superuser". On the contrary, it can signal background workers, including the logical replication launcher. It can signal autovacuum workers and the autovacuum launcher. Signaling autovacuum workers and those two launchers provides no meaningful exploit, so exploiting this vulnerability requires a non-core extension with a less-resilient background worker. For example, a non-core background worker that does not auto-restart would experience a denial of service with respect to that particular background worker. The PostgreSQL project thanks Hemanth Sandrana and Mahendrakar Srinivasarao for reporting this problem.

以上保留官方英文漏洞说明。

本分支修复于:13.13。组件:core server。

官方受影响分支记录:13。

AV:N/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:L

发布说明中的提及:

CVE-2023-5869 · Buffer overrun from integer overflow in array modification · CVSS 8.8

While modifying certain SQL array values, missing overflow checks let authenticated database users write arbitrary bytes to a memory area that facilitates arbitrary code execution. Missing overflow checks also let authenticated database users read a wide area of server memory. The CVE-2021-32027 fix covered some attacks of this description, but it missed others. The PostgreSQL project thanks Pedro Gallegos for reporting this problem.

以上保留官方英文漏洞说明。

本分支修复于:13.13。组件:core server。

官方受影响分支记录:13。

AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

发布说明中的提及:

CVE-2023-5868 · Memory disclosure in aggregate function calls · CVSS 4.3

Certain aggregate function calls receiving "unknown"-type arguments could disclose bytes of server memory from the end of the "unknown"-type value to the next zero byte. One typically gets an "unknown"-type value via a string literal having no type designation. We have not confirmed or ruled out viability of attacks that arrange for presence of notable, confidential information in disclosed bytes. The PostgreSQL project thanks Jingzhou Fu for reporting this problem.

以上保留官方英文漏洞说明。

本分支修复于:13.13。组件:core server。

官方受影响分支记录:13。

AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

发布说明中的提及:

CVE-2023-39417 · Extension script @substitutions@ within quoting allow SQL injection · CVSS 7.5

An extension script is vulnerable if it uses @extowner@ , @extschema@ , or @extschema:...@ inside a quoting construct (dollar quoting, '' , or "" ). No bundled extension is vulnerable. Vulnerable uses do appear in a documentation example and in non-bundled extensions. Hence, the attack prerequisite is an administrator having installed files of a vulnerable, trusted, non-bundled extension. Subject to that prerequisite, this enables an attacker having database-level CREATE privilege to execute arbitrary code as the bootstrap superuser. PostgreSQL will block this attack in the core server, so there's no need to modify individual extensions. The PostgreSQL project thanks Micah Gates, Valerie Woolard, Tim Carey-Smith, and Christoph Berg for reporting this problem.

以上保留官方英文漏洞说明。

本分支修复于:13.12。组件:core server。

官方受影响分支记录:13。

AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H

发布说明中的提及:

CVE-2023-2455 · Row security policies disregard user ID changes after inlining · CVSS 4.2

While CVE-2016-2193 fixed most interaction between row security and user ID changes, it missed a scenario involving function inlining. This leads to potentially incorrect policies being applied in cases where role-specific policies are used and a given query is planned under one role and then executed under other roles. This scenario can happen under security definer functions or when a common user and query is planned initially and then re-used across multiple SET ROLE s. Applying an incorrect policy may permit a user to complete otherwise-forbidden reads and modifications. This affects only databases that have used CREATE POLICY to define a row security policy. The PostgreSQL project thanks Wolfgang Walther for reporting this problem.

以上保留官方英文漏洞说明。

本分支修复于:13.11。组件:core server。

官方受影响分支记录:13。

AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N

发布说明中的提及:

CVE-2023-2454 · CREATE SCHEMA ... schema_element defeats protective search_path changes · CVSS 7.2

This enabled an attacker having database-level CREATE privilege to execute arbitrary code as the bootstrap superuser. Database owners have that right by default, and explicit grants may extend it to other users. The PostgreSQL project thanks Alexander Lakhin for reporting this problem.

以上保留官方英文漏洞说明。

本分支修复于:13.11。组件:core server。

官方受影响分支记录:13。

AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

发布说明中的提及:

CVE-2022-41862 · Client memory disclosure when connecting, with Kerberos, to modified server · CVSS 3.7

A modified, unauthenticated server can send an unterminated string during the establishment of Kerberos transport encryption. When a libpq client application has a Kerberos credential cache and doesn't explicitly disable option gssencmode , a server can cause libpq to over-read and report an error message containing uninitialized bytes from and following its receive buffer. If libpq's caller somehow makes that message accessible to the attacker, this achieves a disclosure of the over-read bytes. We have not confirmed or ruled out viability of attacks that arrange for a crash or for presence of notable, confidential information in disclosed bytes. The PostgreSQL project thanks Jacob Champion for reporting this problem.

以上保留官方英文漏洞说明。

本分支修复于:13.10。组件:client。

官方受影响分支记录:13。

AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N

发布说明中的提及:

CVE-2022-2625 · Extension scripts replace objects not belonging to the extension · CVSS 7.1

Some extensions use CREATE OR REPLACE or CREATE IF NOT EXISTS commands. Some don't adhere to the documented rule to target only objects known to be extension members already. An attack requires permission to create non-temporary objects in at least one schema, ability to lure or wait for an administrator to create or update an affected extension in that schema, and ability to lure or wait for a victim to use the object targeted in CREATE OR REPLACE or CREATE IF NOT EXISTS . Given all three prerequisites, the attacker can run arbitrary code as the victim role, which may be a superuser. Known-affected extensions include both PostgreSQL-bundled and non-bundled extensions. PostgreSQL is blocking this attack in the core server, so there's no need to modify individual extensions. The PostgreSQL project thanks Sven Klemm for reporting this problem.

以上保留官方英文漏洞说明。

本分支修复于:13.8。组件:core server。

官方受影响分支记录:13。

AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H

发布说明中的提及:

CVE-2022-1552 · Autovacuum, REINDEX, and others omit "security restricted operation" sandbox · CVSS 8.8

Autovacuum, REINDEX , CREATE INDEX , REFRESH MATERIALIZED VIEW , CLUSTER , and pg_amcheck made incomplete efforts to operate safely when a privileged user is maintaining another user's objects. Those commands activated relevant protections too late or not at all. An attacker having permission to create non-temp objects in at least one schema could execute arbitrary SQL functions under a superuser identity. While promptly updating PostgreSQL is the best remediation for most users, a user unable to do that can work around the vulnerability by disabling autovacuum, not manually running the above commands, and not restoring from output of the pg_dump command. Performance may degrade quickly under this workaround. VACUUM is safe, and all commands are fine when a trusted user owns the target object. The PostgreSQL project thanks Alexander Lakhin for reporting this problem.

以上保留官方英文漏洞说明。

本分支修复于:13.7。组件:core server。

官方受影响分支记录:13。

AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

发布说明中的提及:

CVE-2021-3677 · Memory disclosure in certain queries · CVSS 6.5

A purpose-crafted query can read arbitrary bytes of server memory. In the default configuration, any authenticated database user can complete this attack at will. The attack does not require the ability to create objects. If server settings include max_worker_processes=0 , the known versions of this attack are infeasible. However, undiscovered variants of the attack may be independent of that setting.

以上保留官方英文漏洞说明。

本分支修复于:13.4。组件:core server。

官方受影响分支记录:13。

AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

发布说明中的提及:

CVE-2021-3449 · CVE-2021-3449

尚未记录本分支的修复版本。

发布说明中的提及:

CVE-2021-3393 · Partition constraint violation errors leak values of denied columns · CVSS 3.1

A user having an UPDATE privilege on a partitioned table but lacking the SELECT privilege on some column may be able to acquire denied-column values from an error message. This is similar to CVE-2014-8161 , but the conditions to exploit are more rare. The PostgreSQL project thanks Heikki Linnakangas for reporting this problem.

以上保留官方英文漏洞说明。

本分支修复于:13.2。组件:core server。

官方受影响分支记录:13。

AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N

发布说明中的提及:

CVE-2021-32029 · Memory disclosure in partitioned-table UPDATE ... RETURNING · CVSS 6.5

Using an UPDATE ... RETURNING on a purpose-crafted partitioned table, an attacker can read arbitrary bytes of server memory. In the default configuration, any authenticated database user can create prerequisite objects and complete this attack at will. A user lacking the CREATE and TEMPORARY privileges on all databases and the CREATE privilege on all schemas typically cannot use this attack at will. The PostgreSQL project thanks Tom Lane for reporting this problem.

以上保留官方英文漏洞说明。

本分支修复于:13.3。组件:core server。

官方受影响分支记录:13。

AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

发布说明中的提及:

CVE-2021-32028 · Memory disclosure in INSERT ... ON CONFLICT ... DO UPDATE · CVSS 6.5

Using an INSERT ... ON CONFLICT ... DO UPDATE command on a purpose-crafted table, an attacker can read arbitrary bytes of server memory. In the default configuration, any authenticated database user can create prerequisite objects and complete this attack at will. A user lacking the CREATE and TEMPORARY privileges on all databases and the CREATE privilege on all schemas cannot use this attack at will. The PostgreSQL project thanks Andres Freund for reporting this problem.

以上保留官方英文漏洞说明。

本分支修复于:13.3。组件:core server。

官方受影响分支记录:13。

AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

发布说明中的提及:

CVE-2021-32027 · Buffer overrun from integer overflow in array subscripting calculations · CVSS 6.5

While modifying certain SQL array values, missing bounds checks let authenticated database users write arbitrary bytes to a wide area of server memory. The PostgreSQL project thanks Tom Lane for reporting this problem.

以上保留官方英文漏洞说明。

本分支修复于:13.3。组件:core server。

官方受影响分支记录:13。

AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N

发布说明中的提及:

CVE-2021-23222 · libpq processes unencrypted bytes from man-in-the-middle · CVSS 3.7

A man-in-the-middle attacker can inject false responses to the client's first few queries, despite the use of SSL certificate verification and encryption. If more preconditions hold, the attacker can exfiltrate the client's password or other confidential data that might be transmitted early in a session. The attacker must have a way to trick the client's intended server into making the confidential data accessible to the attacker. A known implementation having that property is a PostgreSQL configuration vulnerable to CVE-2021-23214 . As with any exploitation of CVE-2021-23214 , the server must be using trust authentication with a clientcert requirement or using cert authentication. To disclose a password, the client must be in possession of a password, which is atypical when using an authentication configuration vulnerable to CVE-2021-23214 . The attacker must have some other way to access the server to retrieve the exfiltrated data (a valid, unprivileged login account would be sufficient). The PostgreSQL project thanks Jacob Champion for reporting this problem.

以上保留官方英文漏洞说明。

本分支修复于:13.5。组件:client。

官方受影响分支记录:13。

AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N

发布说明中的提及:

CVE-2021-23214 · Server processes unencrypted bytes from man-in-the-middle · CVSS 8.1

When the server is configured to use trust authentication with a clientcert requirement or to use cert authentication, a man-in-the-middle attacker can inject arbitrary SQL queries when a connection is first established, despite the use of SSL certificate verification and encryption. This is similar to CVE-2011-0411 (different product). The PostgreSQL project thanks Jacob Champion for reporting this problem.

以上保留官方英文漏洞说明。

本分支修复于:13.5。组件:core server。

官方受影响分支记录:13。

AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

发布说明中的提及:

CVE-2021-20229 · Single-column SELECT privilege enables reading all columns · CVSS 3.1

A user having a SELECT privilege on an individual column can craft a special query that returns all columns of the table. Additionally, a stored view that uses column-level privileges will have incomplete column-usage bitmaps. In installations that depend on column-level permissions for security, it is recommended to execute CREATE OR REPLACE on all user-defined views to force them to be re-parsed. The PostgreSQL project thanks Sven Klemm for reporting this problem.

以上保留官方英文漏洞说明。

本分支修复于:13.2。组件:core server。

官方受影响分支记录:13。

AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N

发布说明中的提及:

CVE-2020-25696 · psql's \gset allows overwriting specially treated variables · CVSS 7.5

The \gset meta-command, which sets psql variables based on query results, does not distinguish variables that control psql behavior. If an interactive psql session uses \gset when querying a compromised server, the attacker can execute arbitrary code as the operating system account running psql . Using \gset with a prefix not found among specially treated variables, e.g. any lowercase string, precludes the attack in an unpatched psql . The PostgreSQL project thanks Nick Cleaton for reporting this problem.

以上保留官方英文漏洞说明。

本分支修复于:13.1。组件:client。

官方受影响分支记录:13。

AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H

发布说明中的提及:

CVE-2020-25695 · Multiple features escape "security restricted operation" sandbox · CVSS 8.8

An attacker having permission to create non-temporary objects in at least one schema can execute arbitrary SQL functions under the identity of a superuser. While promptly updating PostgreSQL is the best remediation for most users, a user unable to do that can work around the vulnerability by disabling autovacuum and not manually running ANALYZE , CLUSTER , REINDEX , CREATE INDEX , VACUUM FULL , REFRESH MATERIALIZED VIEW , or a restore from output of the pg_dump command. Performance may degrade quickly under this workaround. VACUUM without the FULL option is safe, and all commands are fine when a trusted user owns the target object. The PostgreSQL project thanks Etienne Stalmans for reporting this problem.

以上保留官方英文漏洞说明。

本分支修复于:13.1。组件:core server。

官方受影响分支记录:13。

AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

发布说明中的提及:

CVE-2020-25694 · Reconnection can downgrade connection security settings · CVSS 8.1

Many PostgreSQL-provided client applications have options that create additional database connections. Some of those applications reuse only the basic connection parameters (e.g. host , user , port ), dropping others. If this drops a security-relevant parameter (e.g. channel_binding , sslmode , requirepeer , gssencmode ), the attacker has an opportunity to complete a MITM attack or observe cleartext transmission. Affected applications are clusterdb , pg_dump , pg_restore , psql , reindexdb , and vacuumdb . The vulnerability arises only if one invokes an affected client application with a connection string containing a security-relevant parameter. This also fixes how the \connect command of psql reuses connection parameters, i.e. all non-overridden parameters from a previous connection string now re-used. The PostgreSQL project thanks Peter Eisentraut for reporting this problem.

以上保留官方英文漏洞说明。

本分支修复于:13.1。组件:client。

官方受影响分支记录:13。

AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

发布说明中的提及:

CVE-2017-7484 · selectivity estimators bypass SELECT privilege checks · CVSS 4.3

尚未记录本分支的修复版本。组件:core server。

AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

发布说明中的提及:

CVE-2012-0868 · Line breaks in object names can be exploited to execute arbitrary SQL when reloading a pg_dump file.

尚未记录本分支的修复版本。

发布说明中的提及:

CVE-2006-2313 · An attacker able to submit crafted strings to an application that will embed those strings in SQL commands can use invalidly-encoded multibyte characters to bypass standard string-escaping methods, resulting in possible SQL injection.

导出此分支 JSON · 比较已收录的发布版本