Postgresql, versions 11.x before 11.5, is vulnerable to a memory disclosure in cross-type comparison for hashed subplan.
CVSS Details
- CVSS 3.1 Base Score: 2.2
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:L/I:N/A:N)
- CVSS 3.0 Base Score: 3.1
- CVSS 3.0 Vector: (CVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade postgresql15Upgrade postgresqlUpgrade postgresql14 | Nov 8, 2019 | Oct 29, 2019 |
| Arch Linux | — | Upgrade to the latest version of Arch Linux | Jul 11, 2025 | Oct 29, 2019 |
| Debian | — | Upgrade postgresql-11 | Aug 13, 2019 | Aug 13, 2019 |
| Freebsd | — | Upgrade postgresql11-serverUpgrade postgresql95-serverUpgrade postgresql94-serverUpgrade postgresql96-serverUpgrade postgresql10-server | Aug 9, 2019 | Aug 8, 2019 |
| Postgres | — | Upgrade to PostgreSQL version 11.5 | Aug 9, 2019 | Aug 9, 2019 |
| Ubuntu | — | Upgrade postgresql-9.5Upgrade postgresql-11Upgrade postgresql-10 | Aug 10, 2019 | Aug 8, 2019 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub