Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-5gp7-j4r7-g66f

Опубликовано: 10 дек. 2023
Источник: github
Github: Не прошло ревью
CVSS3: 2.2

Описание

A flaw was found in PostgreSQL involving the pg_cancel_backend role that signals background workers, including the logical replication launcher, autovacuum workers, and the autovacuum launcher. Successful exploitation requires a non-core extension with a less-resilient background worker and would affect that specific background worker only. This issue may allow a remote high privileged user to launch a denial of service (DoS) attack.

A flaw was found in PostgreSQL involving the pg_cancel_backend role that signals background workers, including the logical replication launcher, autovacuum workers, and the autovacuum launcher. Successful exploitation requires a non-core extension with a less-resilient background worker and would affect that specific background worker only. This issue may allow a remote high privileged user to launch a denial of service (DoS) attack.

EPSS

Процентиль: 70%
0.00645
Низкий

2.2 Low

CVSS3

Дефекты

CWE-400

Связанные уязвимости

CVSS3: 2.2
ubuntu
больше 1 года назад

A flaw was found in PostgreSQL involving the pg_cancel_backend role that signals background workers, including the logical replication launcher, autovacuum workers, and the autovacuum launcher. Successful exploitation requires a non-core extension with a less-resilient background worker and would affect that specific background worker only. This issue may allow a remote high privileged user to launch a denial of service (DoS) attack.

CVSS3: 2.2
redhat
больше 1 года назад

A flaw was found in PostgreSQL involving the pg_cancel_backend role that signals background workers, including the logical replication launcher, autovacuum workers, and the autovacuum launcher. Successful exploitation requires a non-core extension with a less-resilient background worker and would affect that specific background worker only. This issue may allow a remote high privileged user to launch a denial of service (DoS) attack.

CVSS3: 2.2
nvd
больше 1 года назад

A flaw was found in PostgreSQL involving the pg_cancel_backend role that signals background workers, including the logical replication launcher, autovacuum workers, and the autovacuum launcher. Successful exploitation requires a non-core extension with a less-resilient background worker and would affect that specific background worker only. This issue may allow a remote high privileged user to launch a denial of service (DoS) attack.

CVSS3: 4.4
msrc
7 месяцев назад

Описание отсутствует

CVSS3: 2.2
debian
больше 1 года назад

A flaw was found in PostgreSQL involving the pg_cancel_backend role th ...

EPSS

Процентиль: 70%
0.00645
Низкий

2.2 Low

CVSS3

Дефекты

CWE-400