Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2022-1552

Опубликовано: 12 мая 2022
Источник: redhat
CVSS3: 8.8

Описание

A flaw was found in PostgreSQL. There is an issue with incomplete efforts to operate safely when a privileged user is maintaining another user's objects. The Autovacuum, REINDEX, CREATE INDEX, REFRESH MATERIALIZED VIEW, CLUSTER, and pg_amcheck commands activated relevant protections too late or not at all during the process. This flaw allows an attacker with permission to create non-temporary objects in at least one schema to execute arbitrary SQL functions under a superuser identity.

Меры по смягчению последствий

Red Hat has investigated whether a possible mitigation exists for this issue, and has not been able to identify a practical example. Please update the affected package as soon as possible.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat build of QuarkuspostgresqlNot affected
Red Hat Decision Manager 7postgresqlNot affected
Red Hat Enterprise Linux 6postgresqlOut of support scope
Red Hat Enterprise Linux 8libpqNot affected
Red Hat Fuse 7postgresqlNot affected
Red Hat JBoss Enterprise Application Platform 6postgresqlNot affected
Red Hat JBoss Enterprise Application Platform 7postgresqlNot affected
Red Hat Process Automation 7postgresqlNot affected
Red Hat Enterprise Linux 7postgresqlFixedRHSA-2022:516222.06.2022
Red Hat Enterprise Linux 8postgresqlFixedRHSA-2022:480530.05.2022

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-459->CWE-89
https://bugzilla.redhat.com/show_bug.cgi?id=2081126postgresql: Autovacuum, REINDEX, and others omit "security restricted operation" sandbox

8.8 High

CVSS3

Связанные уязвимости

CVSS3: 8.8
ubuntu
почти 3 года назад

A flaw was found in PostgreSQL. There is an issue with incomplete efforts to operate safely when a privileged user is maintaining another user's objects. The Autovacuum, REINDEX, CREATE INDEX, REFRESH MATERIALIZED VIEW, CLUSTER, and pg_amcheck commands activated relevant protections too late or not at all during the process. This flaw allows an attacker with permission to create non-temporary objects in at least one schema to execute arbitrary SQL functions under a superuser identity.

CVSS3: 8.8
nvd
почти 3 года назад

A flaw was found in PostgreSQL. There is an issue with incomplete efforts to operate safely when a privileged user is maintaining another user's objects. The Autovacuum, REINDEX, CREATE INDEX, REFRESH MATERIALIZED VIEW, CLUSTER, and pg_amcheck commands activated relevant protections too late or not at all during the process. This flaw allows an attacker with permission to create non-temporary objects in at least one schema to execute arbitrary SQL functions under a superuser identity.

CVSS3: 8.8
msrc
почти 3 года назад

Описание отсутствует

CVSS3: 8.8
debian
почти 3 года назад

A flaw was found in PostgreSQL. There is an issue with incomplete effo ...

suse-cvrf
около 3 лет назад

Security update for postgresql14

8.8 High

CVSS3