Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2022-26520

Опубликовано: 01 фев. 2022
Источник: redhat
CVSS3: 9.8
EPSS Низкий

Описание

In pgjdbc before 42.3.3, an attacker (who controls the jdbc URL or properties) can call java.util.logging.FileHandler to write to arbitrary files through the loggerFile and loggerLevel connection properties. An example situation is that an attacker could create an executable JSP file under a Tomcat web root. NOTE: the vendor's position is that there is no pgjdbc vulnerability; instead, it is a vulnerability for any application to use the pgjdbc driver with untrusted connection properties

A flaw was found in Postgres JDBC. This flaw allows an attacker to use a method to write arbitrary files through the connection properties settings. For example, an attacker can create an executable file under the server the application is running and make it a new part of the application or server.

Отчет

Red Hat informs that although there's a difference from NVD CVSSv3 score there's a especial occasion in this CVE that maintain it as a moderate. The scenario for an attacker to get a benefit in this situation requires them to have access to modify a configuration file and write a file where it's needed. This require non-default configuration and also it's not expected to allow an untrusted user to perform this kind of setting.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat build of Debezium 1jdbc-postgresqlAffected
Red Hat build of Quarkusquarkus-jdbc-postgresqlNot affected
Red Hat Enterprise Linux 6postgresql-jdbcOut of support scope
Red Hat Enterprise Linux 7postgresql-jdbcOut of support scope
Red Hat Enterprise Linux 8libreoffice:flatpak/postgresql-jdbcNot affected
Red Hat Enterprise Linux 8postgresql-jdbcNot affected
Red Hat Enterprise Linux 9libreoffice:flatpak/postgresql-jdbcNot affected
Red Hat Enterprise Linux 9postgresql-jdbcNot affected
Red Hat Integration Camel K 1jdbc-postgresqlWill not fix
Red Hat Integration Camel Quarkus 1jdbc-postgresqlNot affected

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-552
https://bugzilla.redhat.com/show_bug.cgi?id=2064007postgresql-jdbc: Arbitrary File Write Vulnerability

EPSS

Процентиль: 69%
0.00622
Низкий

9.8 Critical

CVSS3

Связанные уязвимости

CVSS3: 9.8
ubuntu
больше 3 лет назад

** DISPUTED ** In pgjdbc before 42.3.3, an attacker (who controls the jdbc URL or properties) can call java.util.logging.FileHandler to write to arbitrary files through the loggerFile and loggerLevel connection properties. An example situation is that an attacker could create an executable JSP file under a Tomcat web root. NOTE: the vendor's position is that there is no pgjdbc vulnerability; instead, it is a vulnerability for any application to use the pgjdbc driver with untrusted connection properties.

CVSS3: 9.8
nvd
больше 3 лет назад

In pgjdbc before 42.3.3, an attacker (who controls the jdbc URL or properties) can call java.util.logging.FileHandler to write to arbitrary files through the loggerFile and loggerLevel connection properties. An example situation is that an attacker could create an executable JSP file under a Tomcat web root. NOTE: the vendor's position is that there is no pgjdbc vulnerability; instead, it is a vulnerability for any application to use the pgjdbc driver with untrusted connection properties

CVSS3: 9.8
debian
больше 3 лет назад

In pgjdbc before 42.3.3, an attacker (who controls the jdbc URL or pro ...

suse-cvrf
почти 3 года назад

Security update for postgresql-jdbc

suse-cvrf
почти 3 года назад

Feature update for ongres-scram, ongres-stringprep, postgresql-jdbc

EPSS

Процентиль: 69%
0.00622
Низкий

9.8 Critical

CVSS3