{"id":"CVE-2023-22847","details":"Information disclosure vulnerability exists in pg_ivm versions prior to 1.5.1. An Incrementally Maintainable Materialized View (IMMV) created by pg_ivm may reflect rows with Row-Level Security that the owner of the IMMV should not have access to. As a result, information in tables protected by Row-Level Security may be retrieved by a user who is not authorized to access it.","modified":"2026-08-12T03:51:25.972006390Z","published":"2023-03-07T00:00:00Z","database_specific":{"cna_assigner":"jpcert","osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2023/22xxx/CVE-2023-22847.json"},"references":[{"type":"WEB","url":"https://github.com/sraoss/pg_ivm/releases/tag/v1.5.1"},{"type":"WEB","url":"https://jvn.jp/en/jp/JVN19872280/"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2023/22xxx/CVE-2023-22847.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2023-22847"},{"type":"PACKAGE","url":"https://github.com/sraoss/pg_ivm"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/sraoss/pg_ivm","events":[{"introduced":"a81c657223261ecb565036020eeb8ffacfe938ea"},{"fixed":"a81c657223261ecb565036020eeb8ffacfe938ea"}],"database_specific":{"cpe":"cpe:2.3:a:sraoss:pg_ivm:*:*:*:*:*:postgresql:*:*","extracted_events":[{"introduced":"versions prior to 1.5.1"},{"last_affected":"versions prior to 1.5.1"},{"introduced":"0"},{"fixed":"1.5.1"}],"source":["AFFECTED_FIELD","CPE_RANGE","REFERENCES"]}}],"versions":["versions prior to 1.5.1"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2023-22847.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N"}]}