Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2022-2625

Опубликовано: 18 авг. 2022
Источник: debian
EPSS Низкий

Описание

A vulnerability was found in PostgreSQL. This attack requires permission to create non-temporary objects in at least one schema, the ability to lure or wait for an administrator to create or update an affected extension in that schema, and the ability to lure or wait for a victim to use the object targeted in CREATE OR REPLACE or CREATE IF NOT EXISTS. Given all three prerequisites, this flaw allows an attacker to run arbitrary code as the victim role, which may be a superuser.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
postgresql-14fixed14.5-1package
postgresql-13removedpackage
postgresql-13fixed13.8-0+deb11u1bullseyepackage
postgresql-11removedpackage

Примечания

  • https://www.postgresql.org/support/security/CVE-2022-2625/

EPSS

Процентиль: 71%
0.00705
Низкий

Связанные уязвимости

CVSS3: 8
ubuntu
почти 3 года назад

A vulnerability was found in PostgreSQL. This attack requires permission to create non-temporary objects in at least one schema, the ability to lure or wait for an administrator to create or update an affected extension in that schema, and the ability to lure or wait for a victim to use the object targeted in CREATE OR REPLACE or CREATE IF NOT EXISTS. Given all three prerequisites, this flaw allows an attacker to run arbitrary code as the victim role, which may be a superuser.

CVSS3: 7.1
redhat
почти 3 года назад

A vulnerability was found in PostgreSQL. This attack requires permission to create non-temporary objects in at least one schema, the ability to lure or wait for an administrator to create or update an affected extension in that schema, and the ability to lure or wait for a victim to use the object targeted in CREATE OR REPLACE or CREATE IF NOT EXISTS. Given all three prerequisites, this flaw allows an attacker to run arbitrary code as the victim role, which may be a superuser.

CVSS3: 8
nvd
почти 3 года назад

A vulnerability was found in PostgreSQL. This attack requires permission to create non-temporary objects in at least one schema, the ability to lure or wait for an administrator to create or update an affected extension in that schema, and the ability to lure or wait for a victim to use the object targeted in CREATE OR REPLACE or CREATE IF NOT EXISTS. Given all three prerequisites, this flaw allows an attacker to run arbitrary code as the victim role, which may be a superuser.

CVSS3: 8
msrc
почти 3 года назад

Описание отсутствует

suse-cvrf
почти 3 года назад

Security update for postgresql14

EPSS

Процентиль: 71%
0.00705
Низкий