Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
PostgreSQL 7.4 before 7.4.29, 8.0 before 8.0.25, 8.1 before 8.1.21, 8.2 before 8.2.17, 8.3 before 8.3.11, and 8.4 before 8.4.4 does not properly check privileges during certain RESET ALL operations, which allows remote authenticated users to remove arbitrary parameter settings via a (1) ALTER USER or (2) ALTER DATABASE statement.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
PostgreSQL RESET ALL操作过程访问控制漏洞
Vulnerability Description
PostgreSQL是一款高级对象-关系型数据库管理系统,支持扩展的SQL标准子集。 PostgreSQL在某些RESET ALL操作过程中,没有进行适当的权限检验,远程认证用户可通过(1)ALTER USER,或(2)ALTER DATABASE语句删除任意参数设置。
CVSS Information
N/A
Vulnerability Type
N/A