Loading HuntDB...

GHSA-pcph-v7q2-77cx

GitHub Security Advisory

⚠ Unreviewed MODERATE Has CVE

Advisory Details

INSERT ... ON CONFLICT DO UPDATE commands in PostgreSQL 10.x before 10.1, 9.6.x before 9.6.6, and 9.5.x before 9.5.10 disclose table contents that the invoker lacks privilege to read. These exploits affect only tables where the attacker lacks full read access but has both INSERT and UPDATE privileges. Exploits bypass row level security policies and lack of SELECT privilege.

Related CVEs

Key Information

GHSA ID
GHSA-pcph-v7q2-77cx
Published
May 14, 2022 3:04 AM
Last Modified
April 20, 2025 3:48 AM
CVSS Score
5.0 /10
Primary Ecosystem
Unknown
Primary Package
Unknown
GitHub Reviewed
✗ No

Dataset

Last updated: November 25, 2025 6:29 AM

Data from GitHub Advisory Database. This information is provided for research and educational purposes.