Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-qp83-ppf3-v924

Опубликовано: 13 авг. 2026
Источник: github
Github: Не прошло ревью
CVSS3: 3.8

Описание

Untrusted search path in PostgreSQL amcheck allows a grantee of amcheck function EXECUTE privilege to execute arbitrary functions as the owners of expression indexes that depend on the search path, via setting a hostile search path before calling the amcheck function. Within major versions 18, 16, 15, and 14, minor versions before PostgreSQL 18.5, 16.15, 15.19, and 14.24 are affected. PostgreSQL 17 is unaffected.

Untrusted search path in PostgreSQL amcheck allows a grantee of amcheck function EXECUTE privilege to execute arbitrary functions as the owners of expression indexes that depend on the search path, via setting a hostile search path before calling the amcheck function. Within major versions 18, 16, 15, and 14, minor versions before PostgreSQL 18.5, 16.15, 15.19, and 14.24 are affected. PostgreSQL 17 is unaffected.

EPSS

Процентиль: 19%
0.00269
Низкий

3.8 Low

CVSS3

Дефекты

CWE-426

Связанные уязвимости

CVSS3: 3.8
ubuntu
11 дней назад

Untrusted search path in PostgreSQL amcheck allows a grantee of amcheck function EXECUTE privilege to execute arbitrary functions as the owners of expression indexes that depend on the search path, via setting a hostile search path before calling the amcheck function. Within major versions 18, 16, 15, and 14, minor versions before PostgreSQL 18.5, 16.15, 15.19, and 14.24 are affected. PostgreSQL 17 is unaffected.

CVSS3: 3.8
nvd
11 дней назад

Untrusted search path in PostgreSQL amcheck allows a grantee of amcheck function EXECUTE privilege to execute arbitrary functions as the owners of expression indexes that depend on the search path, via setting a hostile search path before calling the amcheck function. Within major versions 18, 16, 15, and 14, minor versions before PostgreSQL 18.5, 16.15, 15.19, and 14.24 are affected. PostgreSQL 17 is unaffected.

CVSS3: 3.8
debian
11 дней назад

Untrusted search path in PostgreSQL amcheck allows a grantee of amchec ...

CVSS3: 3.8
fstec
11 дней назад

Уязвимость расширения amcheck системы управления базами данных PostgreSQL, позволяющая нарушителю повысить свои привилегии и выполнить произвольный код

EPSS

Процентиль: 19%
0.00269
Низкий

3.8 Low

CVSS3

Дефекты

CWE-426