PostgreSQL Data Exposure Due to INSERT ON CONFLICT Vulnerability
CVE-2017-15099
What is CVE-2017-15099?
This vulnerability in PostgreSQL allows attackers to gain unauthorized access to sensitive table contents through the use of INSERT ... ON CONFLICT DO UPDATE commands. The flaw exists in PostgreSQL versions 10.x prior to 10.1, 9.6.x prior to 9.6.6, and 9.5.x prior to 9.5.10, where users lacking SELECT privileges can exploit INSERT and UPDATE capabilities to bypass row-level security policies, exposing data they are otherwise restricted from viewing. This could lead to significant confidentiality and integrity issues within affected database systems.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
postgresql 10.x before 10.1, 9.6.x before 9.6.6, 9.5.x before 9.5.10
References
EPSS Score
30% chance of being exploited in the next 30 days.
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved