Related Vulnerabilities: CVE-2021-3393  

A security issue was found in PostgreSQL before version 13.2. If a cross-partition UPDATE violates a constraint on the target partition, and the columns in the new partition are in different physical order than in the parent, the error message can reveal columns that the user does not have SELECT permission on.

Severity Medium

Remote Yes

Type Information disclosure

Description

A security issue was found in PostgreSQL before version 13.2. If a cross-partition UPDATE violates a constraint on the target partition, and the columns in the new partition are in different physical order than in the parent, the error message can reveal columns that the user does not have SELECT permission on.

AVG-1567 postgresql 13.1-3 Medium Vulnerable

https://github.com/postgres/postgres/commit/8e56684d54d44ba4ed737d5847d31fba6fb13763