Описание
Missing authorization in PostgreSQL logical decoding allows a non-superuser holding REPLICATION privilege to dlopen any file visible to the operating system account running the server, via the choice of logical decoding plugin. This in turn runs arbitrary code as that account. Versions before PostgreSQL 18.5, 17.11, 16.15, 15.19, and 14.24 are affected.
A flaw was found in PostgreSQL. Missing authorization in PostgreSQL's logical decoding feature allows a non-superuser with REPLICATION privilege to load arbitrary files. This can lead to arbitrary code execution as the operating system account running the server.
Отчет
Important: This flaw in PostgreSQL's logical decoding feature allows a non-superuser with the REPLICATION privilege to execute arbitrary code. Exploitation requires an attacker to already have significant access to the database, specifically the REPLICATION role, which is not granted by default to typical users, thus reducing the overall risk.
Меры по смягчению последствий
To mitigate this vulnerability, ensure that the REPLICATION privilege is granted only to highly trusted database superusers. Regularly review user privileges to confirm that non-superuser accounts do not possess the REPLICATION privilege unless absolutely necessary and their activities are closely monitored. If logical decoding is not actively used, consider disabling it to further reduce the attack surface, though specific configuration steps for disabling logical decoding are beyond the scope of this mitigation.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat Enterprise Linux 10 | postgresql16 | Affected | ||
| Red Hat Enterprise Linux 10 | postgresql18 | Affected | ||
| Red Hat Enterprise Linux 6 | postgresql | Not affected | ||
| Red Hat Enterprise Linux 7 | postgresql | Not affected | ||
| Red Hat Enterprise Linux 8 | postgresql:12/postgresql | Affected | ||
| Red Hat Enterprise Linux 8 | postgresql:15/postgresql | Affected | ||
| Red Hat Enterprise Linux 8 | postgresql:16/postgresql | Affected | ||
| Red Hat Enterprise Linux 9 | postgresql | Affected | ||
| Red Hat Enterprise Linux 9 | postgresql:15/postgresql | Affected | ||
| Red Hat Enterprise Linux 9 | postgresql:16/postgresql | Affected |
Показывать по
Дополнительная информация
Статус:
7.2 High
CVSS3
Связанные уязвимости
Missing authorization in PostgreSQL logical decoding allows a non-superuser holding REPLICATION privilege to dlopen any file visible to the operating system account running the server, via the choice of logical decoding plugin. This in turn runs arbitrary code as that account. Versions before PostgreSQL 18.5, 17.11, 16.15, 15.19, and 14.24 are affected.
Missing authorization in PostgreSQL logical decoding allows a non-superuser holding REPLICATION privilege to dlopen any file visible to the operating system account running the server, via the choice of logical decoding plugin. This in turn runs arbitrary code as that account. Versions before PostgreSQL 18.6, 17.11, 16.15, 15.19, and 14.24 are affected.
Missing authorization in PostgreSQL logical decoding allows a non-supe ...
Missing authorization in PostgreSQL logical decoding allows a non-superuser holding REPLICATION privilege to dlopen any file visible to the operating system account running the server, via the choice of logical decoding plugin. This in turn runs arbitrary code as that account. Versions before PostgreSQL 18.5, 17.11, 16.15, 15.19, and 14.24 are affected.
7.2 High
CVSS3