PostgreSQL Incorrect Authorization Vulnerability - CVE-2021-20229
A flaw was found in PostgreSQL in versions before 13.2 before 12.6 before 11.11 before 10.16 before 9.6.21 and before 9.5.25. This flaw allows a user with SELECT privilege on one column to craft a special query that returns all columns of the table. The highest threat from this vulnerability is to confidentiality.