یادآوری: اطلاعات این سامانه از منابع معرفی‌شده گردآوری می‌شود. پیش از هر اقدام فنی، جزئیات را در منبع اصلی بررسی کنید.
بحرانی اولویت 51/100

17

Security Information The PostgreSQL Global Development Group (PGDG) takes security seriously. This allows our users to place their trust in PostgreSQL for protecting their mission-critical data. The PostgreSQL Global Development Group follows a model that shares responsibility between PostgreSQL itself and its deployment environment, including hardware, operating system, and the application layer (programming language, frameworks and client libraries). The PostgreSQL documentation provides info on the inherent security features of PostgreSQL and how to securely configure and run PostgreSQL. Security vulnerabilities can exist both in PostgreSQL and software within the PostgreSQL ecosystem, including client libraries, extensions, installers, and other utilities. This page walks through what is considered a…

انتشار: — آخرین مشاهده داده: 2026-08-18 19:25 1 منبع · 1 رسمیاعتماد متوسط · 51/100
اولویت VulnWatch 51/100 ترکیب سیگنال‌های ریسک موجود
CVSS / EPSS — / — شدت فنی / احتمال بهره‌برداری
کیفیت داده 50/100 نیازمند توجه · اعتماد متوسط
تازگی داده قدیمی قدیمی‌تر از ۳۰ روز · 1 منبع
راهنمای اقدام

الان چه کاری باید انجام شود؟

پایش و ارزیابی
کیفیت داده 50/100نیازمند توجه · 1 منبع؛ پیش از تغییر Production منبع اصلی را بررسی کنید.
راهکارراهکار ساختاریافته هنوز ثبت نشده است؛ مراجع اصلی را بررسی کنید.
رفتن به راهکار این راهنمای اقدام، RiskScorer را تغییر نمی‌دهد و جایگزین ارزیابی محیط شما نیست.
اولویت عملیاتی 2.5

چرا این مورد باید بررسی شود؟

این امتیاز مستقل از RiskScorer است و برای مرتب‌سازی اقدام‌های عملیاتی استفاده می‌شود.

Priority38
شدت بحرانی
01

خلاصه آسیب‌پذیری

Security Information The PostgreSQL Global Development Group (PGDG) takes security seriously. This allows our users to place their trust in PostgreSQL for protecting their mission-critical data. The PostgreSQL Global Development Group follows a model that shares responsibility between PostgreSQL itself and its deployment environment, including hardware, operating system, and the application layer (programming language, frameworks and client libraries). The PostgreSQL documentation provides info on the inherent security features of PostgreSQL and how to securely configure and run PostgreSQL. Security vulnerabilities can exist both in PostgreSQL and software within the PostgreSQL ecosystem, including client libraries, extensions, installers, and other utilities. This page walks through what is considered a…
02

توضیحات کامل

Security Information The PostgreSQL Global Development Group (PGDG) takes security seriously. This allows our users to place their trust in PostgreSQL for protecting their mission-critical data. The PostgreSQL Global Development Group follows a model that shares responsibility between PostgreSQL itself and its deployment environment, including hardware, operating system, and the application layer (programming language, frameworks and client libraries). The PostgreSQL documentation provides info on the inherent security features of PostgreSQL and how to securely configure and run PostgreSQL. Security vulnerabilities can exist both in PostgreSQL and software within the PostgreSQL ecosystem, including client libraries, extensions, installers, and other utilities. This page walks through what is considered a security vulnerability in PostgreSQL, how to report PostgreSQL security vulnerabilities, and how fixes for security vulnerabilities are released. Please note that the PostgreSQL Project does not offer bug bounties. CVE Numbering Authority The PostgreSQL Project is a CVE Numbering Authority (CNA), working with Red Hat as our CNA Root. This allows us to assign our own CVE numbers and publish CVE records for PostgreSQL and closely related projects. We will currently assign CVE numbers for the following projects upon request to [email protected]: PostgreSQL PostgreSQL RPM packaging PostgreSQL DEB packaging PostgreSQL Windows/macOS installers (EDB) pgJDBC psqlODBC pgAdmin PgBouncer PostgreSQL Anonymizer pgvector Additional projects may request inclusion on the list above by emailing [email protected]. NOTE: The security team will only assign CVEs to projects when requested by members of the project. If you think you've found a security issue in a project other than Postgre
✓

راهکار پیشنهادی برای رفع

اقدام پیشنهادی
در اطلاعات دریافت‌شده هنوز راهکار مشخصی ثبت نشده است.
در اطلاعات دریافت‌شده دستور اجرایی مشخصی پیدا نشد. برای بررسی کامل راهکار، منبع اصلی را باز کنید.
↺

تاریخچه تغییرات معنادار

فقط تغییرات امنیتی مهم مثل KEV، افزایش شدت/CVSS/EPSS، نسخه‌های درگیر و راهکار ثبت می‌شوند.
تاریخچه معنادار از زمان فعال‌شدن موتور 2.5 ساخته می‌شود.
◎

اعتماد، تازگی و پوشش داده

این شاخص عملیاتی از پوشش منابع، کامل‌بودن رکورد، تازگی داده و اختلاف بین منابع ساخته می‌شود و تضمین صحت نیست.
51/100
اعتماد متوسط اعتماد داده 50/100 نیازمند توجه داده قدیمی وضعیت تازگی قدیمی‌تر از ۳۰ روز تازگی مشاهده 63/100 کامل‌بودن · ناقص 52/100 پوشش منابع 1 منبع مرتبط 1 رسمی · 1 سطح ۱ 0 اختلاف بین منابع 3 خلأ کیفیت
PostgreSQL Security رسمی
CVSS
—
شدت
critical
محصول
PostgreSQL / PostgreSQL
نسخه درگیر
—
نسخه اصلاح‌شده
—
تاریخ انتشار منبع
—
⌁

منبع هر داده

برای فیلدهای اصلی می‌توانید ببینید هر مقدار از کدام منبع ثبت شده است. اختلاف بین منابع پنهان نمی‌شود.
توضیحات 1 منبع
PostgreSQL Securityرسمی
Security Information The PostgreSQL Global Development Group (PGDG) takes security seriously. This allows our users to place their trust in PostgreSQL for protecting their mission-critical data. The PostgreSQL Global Development Group follows a model that shares responsibility between PostgreSQL itself and its deployment environment, including hardware, operating system, and the application layer...
منبع ↗
شدت 1 منبع
PostgreSQL Securityرسمی
critical
منبع ↗
خلاصه 1 منبع
PostgreSQL Securityرسمی
Security Information The PostgreSQL Global Development Group (PGDG) takes security seriously. This allows our users to place their trust in PostgreSQL for protecting their mission-critical data. The PostgreSQL Global Development Group follows a model that shares responsibility between PostgreSQL itself and its deployment environment, including hardware, operating system, and the application layer...
منبع ↗
عنوان 1 منبع
PostgreSQL Securityرسمی
17
منبع ↗
↗

منابع و مراجع