CVE-2023-5868: PostgreSQL vulnerability analysis and mitigation
A memory disclosure vulnerability was found in PostgreSQL that allows remote users to access sensitive information by exploiting certain aggregate function calls with 'unknown'-type arguments. Handling 'unknown'-type values from string literals without type designation can disclose bytes, potentially revealing notable and confidential information. This issue exists due to excessive data output in aggregate function calls, enabling remote users to read some portion of system memory.
Source: NVD
Related PostgreSQL vulnerabilities:
CVE ID
Severity
Score
Technologies
Component name
CISA KEV exploit
Has fix
Published date
CVE-2025-8715
HIGH
8.8
PostgreSQL
postgresql-contrib
No
Yes
Aug 14, 2025
CVE-2025-8714
HIGH
8.8
PostgreSQL
postgresql15-plpython3-debuginfo
No
Yes
Aug 14, 2025
CVE-2025-12818
MEDIUM
5.9
PostgreSQL
postgresql16-server-devel
No
Yes
Nov 13, 2025
CVE-2025-12817
LOW
3.1
PostgreSQL
postgresql:15::postgresql-docs
No
Yes
Nov 13, 2025
CVE-2025-8713
LOW
3.1
PostgreSQL
postgresql14-plpython3
No
Yes
Aug 14, 2025
Free Vulnerability Assessment
Benchmark your Cloud Security Posture
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.