CVE-2025-12817lowCWE-862

CVE-2025-12817: fallo de gravedad baja en PostgreSQL

PostgreSQL CREATE STATISTICS does not check for schema CREATE privilege

Publicada el

8Vexday Risk Score

Sin señal de explotación. Ningún artefacto público de explotación conocido hasta ahora.

ssvc Trackcvss 3.1epss 0.2%
probabilidad de explotación
0.2%top 88% de las CVE
explotación observada
noninguna fuente lo reporta
Missing authorization in PostgreSQL CREATE STATISTICS command allows a table owner to achieve denial of service against other CREATE STATISTICS users by creating in any schema. A later CREATE STATISTICS for the same name, from a user having the CREATE privilege, would then fail. Versions before PostgreSQL 18.1, 17.7, 16.11, 15.15, 14.20, and 13.23 are affected.
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:L
Productos afectados
n/a · PostgreSQL