Cyber Resilience

CVE-2024-10976

Postgresql 12.0 – 12.21

Published
14 November 2024
Modified
03 November 2025
Patch / advisory
CVSS Score v3.1 4.2
Click a component to see what it means
Raw vectorCVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N
EPSS Score 0.0079 53th percentile
Risk Priority 37 floored blend · peak EPSS

Summary

CVE-2024-10976 is a medium-severity Improper Preservation of Consistency Between Independent Representations of Shared State (CWE-1250) vulnerability in Postgresql Postgresql. Its CVSS base score is 4.2 (Medium).

Operationally, ranked in the top 47% of CVEs by exploit likelihood; it is not currently listed in the CISA KEV catalog.

EU & UK References

Vulnerability Data

Incomplete tracking in PostgreSQL of tables with row security allows a reused query to view or change different rows from those intended. CVE-2023-2455 and CVE-2016-2193 fixed most interaction between row security and user ID changes. They missed cases where a…

more

subquery, WITH query, security invoker view, or SQL-language function references a table with a row-level security policy. This has the same consequences as the two earlier CVEs. That is to say, it leads to potentially incorrect policies being applied in cases where role-specific policies are used and a given query is planned under one role and then executed under other roles. This scenario can happen under security definer functions or when a common user and query is planned initially and then re-used across multiple SET ROLEs. Applying an incorrect policy may permit a user to complete otherwise-forbidden reads and modifications. This affects only databases that have used CREATE POLICY to define a row security policy. An attacker must tailor an attack to a particular application's pattern of query plan reuse, user ID changes, and role-specific row security policies. Versions before PostgreSQL 17.1, 16.5, 15.9, 14.14, 13.17, and 12.21 are affected.

CWE(s)

Related Threats

CVEs Like This One

CVE-2026-2007Same product: Postgresql Postgresql
CVE-2026-2004Same product: Postgresql Postgresql
CVE-2024-10979Same product: Postgresql Postgresql
CVE-2026-6475Same product: Postgresql Postgresql
CVE-2026-6478Same product: Postgresql Postgresql
CVE-2026-6638Same product: Postgresql Postgresql
CVE-2026-6477Same product: Postgresql Postgresql
CVE-2026-6472Same product: Postgresql Postgresql
CVE-2024-4317Same product: Postgresql Postgresql
CVE-2024-10977Same product: Postgresql Postgresql

Affected Assets

postgresql
postgresql
12.0 — 12.21 · 13.0 — 13.17 · 14.0 — 14.14

Mitigating Controls

Control response

Prevent
Stop it (NIST 800-53)

Detect
Catch it (NIST detect / respond)

Harden
Shrink the surface (DISA STIG)

Validate
Prove the fix (OWASP ASVS)
  • V2.3.4
  • V4.2.1
  • V7.1.3
  • V7.6.1

Mitigating Controls (NIST CSF 2.0) AI

Derived directly from the weakness types (CWEs) cited in the NVD entry via our AI-authored CWE→CSF cross-walk (authority under review) — links open the control.

PR.PS-06 mostly match
prevents

SSDLC practices directly address design-level state-consistency flaws during development.

DE.CM-09 partial match
prevents

Runtime data monitoring can surface consistency violations after they occur.

PR.DS-01 partial match
prevents

Integrity protections such as hashes or signatures can detect or prevent inconsistent state copies.

PR.IR-03 partial match
prevents

Resilience mechanisms often include state synchronization or replication protocols that enforce consistency.

Mitigating Controls (ISO/IEC 27001:2022 Annex A) AI

Derived directly from the weakness types (CWEs) cited in the NVD entry via our AI-authored CWE→ISO cross-walk (authority under review) — links open the control.

prevents

Secure architecture principles can address distributed-state design yet leave the actual consistency mechanisms unspecified.

degrades

Redundancy mechanisms can reduce divergence risk but do not guarantee consistency across independent state copies.

finds

Monitoring can detect inconsistencies after they occur but does not prevent them by design.

prevents

Secure SDLC practices can include consistency requirements yet do not specifically mandate distributed-state synchronization.

prevents

Application security requirements may specify consistency rules but do not guarantee their implementation.

degrades

Change management can coordinate updates across replicas but does not inherently enforce real-time consistency.

References