reshke opened a new pull request, #1551:
URL: https://github.com/apache/cloudberry/pull/1551

   …tats_ext_exprs.
   
   The catalog view pg_stats_ext fails to consider privileges for expression 
statistics.  The catalog view pg_stats_ext_exprs fails to consider privileges 
and row-level security policies.  To fix, restrict the data in these views to 
table owners or roles that inherit privileges of the table owner.  It may be 
possible to apply less restrictive privilege checks in some cases, but that is 
left as a future exercise.  Furthermore, for pg_stats_ext_exprs, do not return 
data for tables with row-level security enabled, as is already done for 
pg_stats_ext.
   
   On the back-branches, a fix-CVE-2024-4317.sql script is provided that will 
install into the "share" directory.  This file can be used to apply the fix to 
existing clusters.
   
   Bumps catversion on 'master' branch only.
   
   Reported-by: Lukas Fittl
   Reviewed-by: Noah Misch, Tomas Vondra, Tom Lane
   Security: CVE-2024-4317
   Backpatch-through: 14


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]


---------------------------------------------------------------------
To unsubscribe, e-mail: [email protected]
For additional commands, e-mail: [email protected]

Reply via email to