Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2020-14349

Опубликовано: 24 авг. 2020
Источник: ubuntu
Приоритет: medium
EPSS Низкий
CVSS2: 4.6
CVSS3: 7.1

Описание

It was found that PostgreSQL versions before 12.4, before 11.9 and before 10.14 did not properly sanitize the search_path during logical replication. An authenticated attacker could use this flaw in an attack similar to CVE-2018-1058, in order to execute arbitrary SQL command in the context of the user used for replication.

РелизСтатусПримечание
bionic

released

10.14-0ubuntu0.18.04.1
devel

DNE

esm-infra-legacy/trusty

DNE

esm-infra/bionic

not-affected

10.14-0ubuntu0.18.04.1
esm-infra/focal

DNE

focal

DNE

precise/esm

DNE

trusty

DNE

trusty/esm

DNE

upstream

released

10.14

Показывать по

РелизСтатусПримечание
bionic

DNE

devel

released

12.4-1
esm-infra-legacy/trusty

DNE

esm-infra/focal

not-affected

12.4-0ubuntu0.20.04.1
focal

released

12.4-0ubuntu0.20.04.1
precise/esm

DNE

trusty

ignored

end of standard support
trusty/esm

DNE

upstream

released

12.4-1
xenial

DNE

Показывать по

РелизСтатусПримечание
bionic

DNE

devel

DNE

esm-infra-legacy/trusty

DNE

esm-infra/focal

DNE

focal

DNE

precise/esm

not-affected

code not present
trusty

ignored

end of standard support
trusty/esm

DNE

upstream

needs-triage

xenial

DNE

Показывать по

РелизСтатусПримечание
bionic

DNE

devel

DNE

esm-infra-legacy/trusty

not-affected

code not present
esm-infra/focal

DNE

focal

DNE

precise/esm

DNE

trusty

ignored

end of standard support
trusty/esm

not-affected

code not present
upstream

needs-triage

xenial

DNE

Показывать по

РелизСтатусПримечание
bionic

DNE

devel

DNE

esm-infra-legacy/trusty

DNE

esm-infra/focal

DNE

esm-infra/xenial

not-affected

code not present
focal

DNE

precise/esm

DNE

trusty

DNE

trusty/esm

DNE

upstream

released

9.5.23

Показывать по

EPSS

Процентиль: 69%
0.00622
Низкий

4.6 Medium

CVSS2

7.1 High

CVSS3

Связанные уязвимости

CVSS3: 7.1
redhat
почти 5 лет назад

It was found that PostgreSQL versions before 12.4, before 11.9 and before 10.14 did not properly sanitize the search_path during logical replication. An authenticated attacker could use this flaw in an attack similar to CVE-2018-1058, in order to execute arbitrary SQL command in the context of the user used for replication.

CVSS3: 7.1
nvd
почти 5 лет назад

It was found that PostgreSQL versions before 12.4, before 11.9 and before 10.14 did not properly sanitize the search_path during logical replication. An authenticated attacker could use this flaw in an attack similar to CVE-2018-1058, in order to execute arbitrary SQL command in the context of the user used for replication.

CVSS3: 7.1
msrc
почти 5 лет назад

Описание отсутствует

CVSS3: 7.1
debian
почти 5 лет назад

It was found that PostgreSQL versions before 12.4, before 11.9 and bef ...

CVSS3: 7.1
github
около 3 лет назад

It was found that PostgreSQL versions before 12.4, before 11.9 and before 10.14 did not properly sanitize the search_path during logical replication. An authenticated attacker could use this flaw in an attack similar to CVE-2018-1058, in order to execute arbitrary SQL command in the context of the user used for replication.

EPSS

Процентиль: 69%
0.00622
Низкий

4.6 Medium

CVSS2

7.1 High

CVSS3