Missing authorization in PostgreSQL CREATE STATISTICS command allows a table owner to achieve denial of service against other CREATE STATISTICS users by creating in any schema. A later CREATE STATISTICS for the same name, from a user having the CREATE privilege, would then fail. Versions before PostgreSQL 18.1, 17.7, 16.11, 15.15, 14.20, and 13.23 are affected.
Metrics
Affected Vendors & Products
References
History
Mon, 17 Nov 2025 12:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
| |
| Metrics |
threat_severity
|
threat_severity
|
Fri, 14 Nov 2025 09:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Postgresql
Postgresql postgresql |
|
| Vendors & Products |
Postgresql
Postgresql postgresql |
Thu, 13 Nov 2025 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 13 Nov 2025 13:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Missing authorization in PostgreSQL CREATE STATISTICS command allows a table owner to achieve denial of service against other CREATE STATISTICS users by creating in any schema. A later CREATE STATISTICS for the same name, from a user having the CREATE privilege, would then fail. Versions before PostgreSQL 18.1, 17.7, 16.11, 15.15, 14.20, and 13.23 are affected. | |
| Title | PostgreSQL CREATE STATISTICS does not check for schema CREATE privilege | |
| Weaknesses | CWE-862 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: PostgreSQL
Published: 2025-11-13T13:00:12.160Z
Updated: 2025-11-13T13:59:54.599Z
Reserved: 2025-11-06T17:22:31.286Z
Link: CVE-2025-12817
Updated: 2025-11-13T13:59:51.843Z
Status : Awaiting Analysis
Published: 2025-11-13T13:15:45.167
Modified: 2025-11-14T16:42:03.187
Link: CVE-2025-12817