Уязвимость выполнения произвольных SQL-функций под учётной записью суперпользователя в PostgreSQL
Описание
В PostgreSQL обнаружена уязвимость, позволяющая злоумышленнику, обладающему правами на создание не временных (non-temporary) объектов хотя бы в одной из схем, выполнять произвольные SQL-функции от имени суперпользователя. Эта уязвимость угрожает конфиденциальности и целостности данных, а также доступности системы.
Затронутые версии ПО
- PostgreSQL версии до 13.1
 - PostgreSQL версии до 12.5
 - PostgreSQL версии до 11.10
 - PostgreSQL версии до 10.15
 - PostgreSQL версии до 9.6.20
 - PostgreSQL версии до 9.5.24
 
Тип уязвимости
Выполнение произвольного кода
Ссылки
- Issue TrackingThird Party Advisory
 - Mailing ListThird Party Advisory
 - Third Party Advisory
 - Third Party Advisory
 - Vendor Advisory
 - Issue TrackingThird Party Advisory
 - Mailing ListThird Party Advisory
 - Third Party Advisory
 - Third Party Advisory
 - Vendor Advisory
 
Уязвимые конфигурации
Одно из
EPSS
8.8 High
CVSS3
6.5 Medium
CVSS2
Дефекты
Связанные уязвимости
A flaw was found in PostgreSQL versions before 13.1, before 12.5, before 11.10, before 10.15, before 9.6.20 and before 9.5.24. An attacker having permission to create non-temporary objects in at least one schema can execute arbitrary SQL functions under the identity of a superuser. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.
A flaw was found in PostgreSQL versions before 13.1, before 12.5, before 11.10, before 10.15, before 9.6.20 and before 9.5.24. An attacker having permission to create non-temporary objects in at least one schema can execute arbitrary SQL functions under the identity of a superuser. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.
A flaw was found in PostgreSQL versions before 13.1 before 12.5 before 11.10 before 10.15 before 9.6.20 and before 9.5.24. An attacker having permission to create non-temporary objects in at least one schema can execute arbitrary SQL functions under the identity of a superuser. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.
A flaw was found in PostgreSQL versions before 13.1, before 12.5, befo ...
EPSS
8.8 High
CVSS3
6.5 Medium
CVSS2