Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2022-2625

Опубликовано: 11 авг. 2022
Источник: redhat
CVSS3: 7.1
EPSS Низкий

Описание

A vulnerability was found in PostgreSQL. This attack requires permission to create non-temporary objects in at least one schema, the ability to lure or wait for an administrator to create or update an affected extension in that schema, and the ability to lure or wait for a victim to use the object targeted in CREATE OR REPLACE or CREATE IF NOT EXISTS. Given all three prerequisites, this flaw allows an attacker to run arbitrary code as the victim role, which may be a superuser.

Отчет

Known-affected extensions include both PostgreSQL-bundled and non-bundled extensions. PostgreSQL blocks this attack in the core server, so there's no need to modify individual extensions.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6postgresqlOut of support scope
Red Hat Enterprise Linux 7postgresqlOut of support scope
Red Hat Software Collectionsrh-postgresql12-postgresqlWill not fix
Red Hat Software Collectionsrh-postgresql13-postgresqlWill not fix
Red Hat Enterprise Linux 8postgresqlFixedRHSA-2022:712825.10.2022
Red Hat Enterprise Linux 8postgresqlFixedRHSA-2023:011312.01.2023
Red Hat Enterprise Linux 8postgresqlFixedRHSA-2023:157604.04.2023
Red Hat Enterprise Linux 8.2 Advanced Update SupportpostgresqlFixedRHSA-2023:766706.12.2023
Red Hat Enterprise Linux 8.2 Telecommunications Update ServicepostgresqlFixedRHSA-2023:766706.12.2023
Red Hat Enterprise Linux 8.2 Update Services for SAP SolutionspostgresqlFixedRHSA-2023:766706.12.2023

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-1321->CWE-915
https://bugzilla.redhat.com/show_bug.cgi?id=2113825postgresql: Extension scripts replace objects not belonging to the extension.

EPSS

Процентиль: 71%
0.00705
Низкий

7.1 High

CVSS3

Связанные уязвимости

CVSS3: 8
ubuntu
почти 3 года назад

A vulnerability was found in PostgreSQL. This attack requires permission to create non-temporary objects in at least one schema, the ability to lure or wait for an administrator to create or update an affected extension in that schema, and the ability to lure or wait for a victim to use the object targeted in CREATE OR REPLACE or CREATE IF NOT EXISTS. Given all three prerequisites, this flaw allows an attacker to run arbitrary code as the victim role, which may be a superuser.

CVSS3: 8
nvd
почти 3 года назад

A vulnerability was found in PostgreSQL. This attack requires permission to create non-temporary objects in at least one schema, the ability to lure or wait for an administrator to create or update an affected extension in that schema, and the ability to lure or wait for a victim to use the object targeted in CREATE OR REPLACE or CREATE IF NOT EXISTS. Given all three prerequisites, this flaw allows an attacker to run arbitrary code as the victim role, which may be a superuser.

CVSS3: 8
msrc
почти 3 года назад

Описание отсутствует

CVSS3: 8
debian
почти 3 года назад

A vulnerability was found in PostgreSQL. This attack requires permissi ...

suse-cvrf
почти 3 года назад

Security update for postgresql14

EPSS

Процентиль: 71%
0.00705
Низкий

7.1 High

CVSS3