CVE-2024-10976
Postgresql 12.0 – 12.21
Raw vector
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:NSummary
CVE-2024-10976 is a medium-severity Improper Preservation of Consistency Between Independent Representations of Shared State (CWE-1250) vulnerability in Postgresql Postgresql. Its CVSS base score is 4.2 (Medium).
Operationally, ranked in the top 47% of CVEs by exploit likelihood; it is not currently listed in the CISA KEV catalog.
EU & UK References
- 🇪🇺 ENISA EUVD: EUVD-2024-33374
Vulnerability Data
Incomplete tracking in PostgreSQL of tables with row security allows a reused query to view or change different rows from those intended. CVE-2023-2455 and CVE-2016-2193 fixed most interaction between row security and user ID changes. They missed cases where a…
more
subquery, WITH query, security invoker view, or SQL-language function references a table with a row-level security policy. This has the same consequences as the two earlier CVEs. That is to say, it leads to potentially incorrect policies being applied in cases where role-specific policies are used and a given query is planned under one role and then executed under other roles. This scenario can happen under security definer functions or when a common user and query is planned initially and then re-used across multiple SET ROLEs. Applying an incorrect policy may permit a user to complete otherwise-forbidden reads and modifications. This affects only databases that have used CREATE POLICY to define a row security policy. An attacker must tailor an attack to a particular application's pattern of query plan reuse, user ID changes, and role-specific row security policies. Versions before PostgreSQL 17.1, 16.5, 15.9, 14.14, 13.17, and 12.21 are affected.
- CWE(s)
Related Threats
CVEs Like This One
Affected Assets
Mitigating Controls
Control response
—
—
—
V2.3.4V4.2.1V7.1.3V7.6.1
Mitigating Controls (NIST CSF 2.0) AI
Derived directly from the weakness types (CWEs) cited in the NVD entry via our AI-authored CWE→CSF cross-walk (authority under review) — links open the control.
SSDLC practices directly address design-level state-consistency flaws during development.
Runtime data monitoring can surface consistency violations after they occur.
Integrity protections such as hashes or signatures can detect or prevent inconsistent state copies.
Resilience mechanisms often include state synchronization or replication protocols that enforce consistency.
Mitigating Controls (ISO/IEC 27001:2022 Annex A) AI
Derived directly from the weakness types (CWEs) cited in the NVD entry via our AI-authored CWE→ISO cross-walk (authority under review) — links open the control.
Secure architecture principles can address distributed-state design yet leave the actual consistency mechanisms unspecified.
Redundancy mechanisms can reduce divergence risk but do not guarantee consistency across independent state copies.
Monitoring can detect inconsistencies after they occur but does not prevent them by design.
Secure SDLC practices can include consistency requirements yet do not specifically mandate distributed-state synchronization.
Application security requirements may specify consistency rules but do not guarantee their implementation.
Change management can coordinate updates across replicas but does not inherently enforce real-time consistency.