#VU40402 Security Features in PostgreSQL - CVE-2016-2193
Published: April 11, 2016 / Updated: August 9, 2020
PostgreSQL
PostgreSQL Global Development Group
Description
The vulnerability allows a remote non-authenticated attacker to manipulate data.
PostgreSQL before 9.5.x before 9.5.2 does not properly maintain row-security status in cached plans, which might allow attackers to bypass intended access restrictions by leveraging a session that performs queries as more than one role.