Postgresql, versions 11.x before 11.5, is vulnerable to a memory disclosure in cross-type comparison for hashed subplan.
CVSS Details
- CVSS 3.1 Base Score: 2.2
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:L/I:N/A:N)
- CVSS 3.0 Base Score: 3.1
- CVSS 3.0 Vector: (CVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade postgresql14Upgrade postgresqlUpgrade postgresql15 | Nov 8, 2019 | Oct 29, 2019 |
| Arch Linux | — | Upgrade to the latest version of Arch Linux | Jul 11, 2025 | Oct 29, 2019 |
| Debian | — | Upgrade postgresql-11 | Aug 13, 2019 | Aug 13, 2019 |
| Freebsd | — | Upgrade postgresql10-serverUpgrade postgresql96-serverUpgrade postgresql94-serverUpgrade postgresql95-serverUpgrade postgresql11-server | Aug 9, 2019 | Aug 8, 2019 |
| Postgres | — | Upgrade to PostgreSQL version 11.5 | Aug 9, 2019 | Aug 9, 2019 |
| Ubuntu | — | Upgrade postgresql-10Upgrade postgresql-11Upgrade postgresql-9.5 | Aug 10, 2019 | Aug 8, 2019 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub