CyberRota Analysis
This is a low severity vulnerability with a CVSS score of 3.1. Exploitation may require the attacker to be authenticated.
CVE
CVE-2020-1720
Severity
LOW
CVSS
3.1
EPSS
1.18%
Original NVD Description
A flaw was found in PostgreSQL's "ALTER ... DEPENDS ON EXTENSION", where sub-commands did not perform authorization checks. An authenticated attacker could use this flaw in certain configurations to perform drop objects such as function, triggers, et al., leading to database corruption. This issue affects PostgreSQL versions before 12.2, before 11.7, before 10.12 and before 9.6.17.
Related CVEs
Other vulnerabilities affecting the same vendor(s)