Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-x9qc-m3q8-9g77

Опубликовано: 12 дек. 2023
Источник: github
Github: Не прошло ревью
CVSS3: 8.8

Описание

An issue was discovered in EnterpriseDB Postgres Advanced Server (EPAS) before 11.21.32, 12.x before 12.16.20, 13.x before 13.12.16, 14.x before 14.9.0, and 15.x before 15.4.0. It contain packages, standalone packages, and functions that run SECURITY DEFINER but are inadequately secured against search_path attacks.

An issue was discovered in EnterpriseDB Postgres Advanced Server (EPAS) before 11.21.32, 12.x before 12.16.20, 13.x before 13.12.16, 14.x before 14.9.0, and 15.x before 15.4.0. It contain packages, standalone packages, and functions that run SECURITY DEFINER but are inadequately secured against search_path attacks.

EPSS

Процентиль: 23%
0.00077
Низкий

8.8 High

CVSS3

Дефекты

CWE-427

Связанные уязвимости

CVSS3: 8.8
nvd
около 2 лет назад

An issue was discovered in EnterpriseDB Postgres Advanced Server (EPAS) before 11.21.32, 12.x before 12.16.20, 13.x before 13.12.16, 14.x before 14.9.0, and 15.x before 15.4.0. It contain packages, standalone packages, and functions that run SECURITY DEFINER but are inadequately secured against search_path attacks.

EPSS

Процентиль: 23%
0.00077
Низкий

8.8 High

CVSS3

Дефекты

CWE-427