Description
PostgreSQL versions 8.4 - 9.6 are vulnerable to information leak in pg_user_mappings view which discloses foreign server passwords to any user having USAGE privilege on the associated foreign server.
Remediation
References
Related Vulnerabilities
Moodle Incorrect Authorization Vulnerability (CVE-2020-25701)
phpMyAdmin Cross-Site Request Forgery (CSRF) Vulnerability (CVE-2015-3902)
MySQL Other Vulnerability (CVE-2010-1849)
Oracle Database Server CVE-2008-2611 Vulnerability (CVE-2008-2611)
Jboss EAP Permissions, Privileges, and Access Controls Vulnerability (CVE-2014-7827)