CVE.RADIO
FREN

CVE-2021-23214

postgresqlVulnerabilityCVSS 8.1Patched

No public exploitation has been reported so far. A fixed version is available (see the table below).

Recommended action: Update to the fixed version listed for your distribution using the native package manager.

Severity metrics

CVSS 3.1 : 8.1 HIGH · CVSS 2.0 : 5.1 MEDIUM

Attack vectorNetwork (remote)
Attack complexityHigh
Privileges requiredNone
User interactionNone
ScopeUnchanged
Confidentiality impactHigh
Integrity impactHigh
Availability impactHigh

Vector: AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

Affected & fixed versions by distribution

Versions are the native distribution strings (backport-aware): RHEL/Debian/SUSE backport fixes, so compare with the distro version comparator (dpkg / rpm / vercmp), not the upstream version.

DistributionPackageAffectedFixed versionStatus
Archpostgresql13.4-613.5-1fixed
SUSE:HPE Helion OpenStack 8postgresql-14-4.10.1fixed
SUSE:OpenStack Cloud 8postgresql-14-4.10.1fixed
SUSE:OpenStack Cloud 9postgresql-14-4.10.1fixed
SUSE:OpenStack Cloud Crowbar 8postgresql-14-4.10.1fixed
SUSE:OpenStack Cloud Crowbar 9postgresql-14-4.10.1fixed
SUSE:Linux Enterprise Server for SAP Applications 12 SP3postgresql-14-4.10.1fixed
SUSE:Linux Enterprise Server for SAP Applications 12 SP4postgresql-14-4.10.1fixed
SUSE:Linux Enterprise Software Development Kit 12 SP5postgresql-14-4.10.1fixed
SUSE:Linux Enterprise Server 12 SP2-BCLpostgresql-14-4.10.1fixed
SUSE:Linux Enterprise Server 12 SP3-LTSSpostgresql-14-4.10.1fixed
SUSE:Linux Enterprise Server 12 SP3-BCLpostgresql-14-4.10.1fixed
SUSE:Linux Enterprise Server 12 SP4-LTSSpostgresql-14-4.10.1fixed
SUSE:Linux Enterprise Server 12 SP5postgresql-14-4.10.1fixed
SUSE:Linux Enterprise Server for SAP Applications 12 SP5postgresql-14-4.10.1fixed
SUSE:Linux Enterprise High Performance Computing 15-ESPOSpostgresql-12.0.1-150000.8.19.1fixed
SUSE:Linux Enterprise High Performance Computing 15-LTSSpostgresql-12.0.1-150000.8.19.1fixed
SUSE:Linux Enterprise High Performance Computing 15 SP1-ESPOSpostgresql-12.0.1-150000.8.19.1fixed
SUSE:Linux Enterprise High Performance Computing 15 SP1-LTSSpostgresql-12.0.1-150000.8.19.1fixed
SUSE:Linux Enterprise Server 15-LTSSpostgresql-12.0.1-150000.8.19.1fixed
SUSE:Linux Enterprise Server 15 SP1-BCLpostgresql-12.0.1-150000.8.19.1fixed
SUSE:Linux Enterprise Server 15 SP1-LTSSpostgresql-12.0.1-150000.8.19.1fixed
SUSE:Linux Enterprise Server for SAP Applications 15postgresql-12.0.1-150000.8.19.1fixed
SUSE:Linux Enterprise Server for SAP Applications 15 SP1postgresql-12.0.1-150000.8.19.1fixed
SUSE:Enterprise Storage 6postgresql-12.0.1-150000.8.19.1fixed
openSUSE:Tumbleweedpostgresql15-15.4-2.1fixed
openSUSE:Tumbleweedpostgresql16-16.4-1.1fixed
Red Hat:enterprise_linux:8::appstreampostgresql-0:12.9-1.module+el8.5.0+13373+4554acc4fixed
Red Hat:enterprise_linux:8::appstreampostgresql-0:13.5-1.module+el8.5.0+13344+8c0fd184fixed
Red Hat:enterprise_linux:8::appstreampostgresql-0:10.19-1.module+el8.6.0+13642+78853f5afixed

Sources