VDB
CVE-2020-21469
CVE-2020-21469
PUBLISHED
An issue was discovered in PostgreSQL 12.2 allows attackers to cause a denial of service via repeatedly sending SIGHUP signals. NOTE: this is disputed by the vendor because untrusted users cannot send SIGHUP signals; they can only be sent by a PostgreSQL superuser, a user with pg_reload_conf access, or a user with sufficient privileges at the OS level (the postgres account or the root account).
EPSS 0.03% · 7.8th percentile
Risk Scores
EPSS Score
0.03%
7.8th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Bitnami | postgresql | 12.2.0 |
| Bitnami | postgresql | 12.2.0 |
Exploit Intelligence
Timeline
- Aug 22, 2023 CVE Published
- Aug 23, 2023 EPSS Score
- Sep 25, 2023 EPSS Score
- Oct 28, 2023 EPSS Score
- Nov 30, 2023 EPSS Score
- Jan 3, 2024 EPSS Score
- Feb 5, 2024 EPSS Score
- Mar 9, 2024 EPSS Score
- Apr 11, 2024 EPSS Score
- May 14, 2024 EPSS Score
- Jun 16, 2024 EPSS Score
- Jul 19, 2024 EPSS Score
References
- https://www.postgresql.org/message-id/CAA8ZSMqAHDCgo07hqKoM5XJaoQy6Vv76O7966agez4ffyQktkA%40mail.gmail.com url
- https://www.postgresql.org/message-id/flat/CAA8ZSMqAHDCgo07hqKoM5XJaoQy6Vv76O7966agez4ffyQktkA%40mail.gmail.com url
- https://www.postgresql.org/support/security/ url
- https://nvd.nist.gov/vuln/detail/CVE-2020-21469 url
- Multiples vulnérabilités dans Juniper Networks Secure Analytics advisory