Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-6v9v-3f4c-cjgx

Опубликовано: 15 фев. 2022
Источник: github
Github: Не прошло ревью
CVSS3: 7.3

Описание

Untrusted Search Path in PostgreSQL

It was found that some PostgreSQL extensions did not use search_path safely in their installation script. An attacker with sufficient privileges could use this flaw to trick an administrator into executing a specially crafted script, during the installation or update of such extension. This affects PostgreSQL versions before 12.4, before 11.9, before 10.14, before 9.6.19, and before 9.5.23.

EPSS

Процентиль: 7%
0.00031
Низкий

7.3 High

CVSS3

Дефекты

CWE-426

Связанные уязвимости

CVSS3: 7.3
ubuntu
почти 5 лет назад

It was found that some PostgreSQL extensions did not use search_path safely in their installation script. An attacker with sufficient privileges could use this flaw to trick an administrator into executing a specially crafted script, during the installation or update of such extension. This affects PostgreSQL versions before 12.4, before 11.9, before 10.14, before 9.6.19, and before 9.5.23.

CVSS3: 7.1
redhat
почти 5 лет назад

It was found that some PostgreSQL extensions did not use search_path safely in their installation script. An attacker with sufficient privileges could use this flaw to trick an administrator into executing a specially crafted script, during the installation or update of such extension. This affects PostgreSQL versions before 12.4, before 11.9, before 10.14, before 9.6.19, and before 9.5.23.

CVSS3: 7.3
nvd
почти 5 лет назад

It was found that some PostgreSQL extensions did not use search_path safely in their installation script. An attacker with sufficient privileges could use this flaw to trick an administrator into executing a specially crafted script, during the installation or update of such extension. This affects PostgreSQL versions before 12.4, before 11.9, before 10.14, before 9.6.19, and before 9.5.23.

CVSS3: 7.3
msrc
почти 5 лет назад

Описание отсутствует

CVSS3: 7.3
debian
почти 5 лет назад

It was found that some PostgreSQL extensions did not use search_path s ...

EPSS

Процентиль: 7%
0.00031
Низкий

7.3 High

CVSS3

Дефекты

CWE-426