Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2025-55282

Опубликовано: 18 авг. 2025
Источник: nvd
CVSS3: 9.1
CVSS3: 7.2
EPSS Низкий

Описание

aiven-db-migrate is an Aiven database migration tool. Prior to 1.0.7, there is a privilege escalation vulnerability that allows a user to elevate to superuser inside PostgreSQL databases during a migration from an untrusted source server. By exploiting a lack of search_path restriction, an attacker can override pg_catalog and execute untrusted operators as a superuser. This vulnerability is fixed in 1.0.7.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:aiven:aiven-db-migrate:*:*:*:*:*:*:*:*
Версия до 1.0.7 (исключая)

EPSS

Процентиль: 23%
0.00077
Низкий

9.1 Critical

CVSS3

7.2 High

CVSS3

Дефекты

CWE-22

EPSS

Процентиль: 23%
0.00077
Низкий

9.1 Critical

CVSS3

7.2 High

CVSS3

Дефекты

CWE-22