Описание
A flaw was found in PostgreSQL. There is an issue with incomplete efforts to operate safely when a privileged user is maintaining another user's objects. The Autovacuum, REINDEX, CREATE INDEX, REFRESH MATERIALIZED VIEW, CLUSTER, and pg_amcheck commands activated relevant protections too late or not at all during the process. This flaw allows an attacker with permission to create non-temporary objects in at least one schema to execute arbitrary SQL functions under a superuser identity.
| Релиз | Статус | Примечание | 
|---|---|---|
| bionic | released  | 10.21-0ubuntu0.18.04.1 | 
| devel | DNE  | |
| esm-infra-legacy/trusty | DNE  | |
| esm-infra/bionic | released  | 10.21-0ubuntu0.18.04.1 | 
| esm-infra/focal | DNE  | |
| focal | DNE  | |
| impish | DNE  | |
| jammy | DNE  | |
| kinetic | DNE  | |
| lunar | DNE  | 
Показывать по
| Релиз | Статус | Примечание | 
|---|---|---|
| bionic | DNE  | |
| devel | DNE  | |
| esm-infra-legacy/trusty | DNE  | |
| esm-infra/focal | released  | 12.11-0ubuntu0.20.04.1 | 
| focal | released  | 12.11-0ubuntu0.20.04.1 | 
| impish | DNE  | |
| jammy | DNE  | |
| kinetic | DNE  | |
| lunar | DNE  | |
| mantic | DNE  | 
Показывать по
| Релиз | Статус | Примечание | 
|---|---|---|
| bionic | DNE  | |
| devel | DNE  | |
| esm-infra-legacy/trusty | DNE  | |
| esm-infra/focal | DNE  | |
| focal | DNE  | |
| impish | released  | 13.7-0ubuntu0.21.10.1 | 
| jammy | DNE  | |
| kinetic | DNE  | |
| lunar | DNE  | |
| mantic | DNE  | 
Показывать по
| Релиз | Статус | Примечание | 
|---|---|---|
| bionic | DNE  | |
| devel | DNE  | |
| esm-infra-legacy/trusty | DNE  | |
| esm-infra/focal | DNE  | |
| focal | DNE  | |
| impish | DNE  | |
| jammy | released  | 14.3-0ubuntu0.22.04.1 | 
| kinetic | not-affected  | 14.3-1 | 
| lunar | DNE  | |
| mantic | DNE  | 
Показывать по
| Релиз | Статус | Примечание | 
|---|---|---|
| bionic | DNE  | |
| devel | DNE  | |
| esm-infra-legacy/trusty | DNE  | |
| esm-infra/focal | DNE  | |
| focal | DNE  | |
| impish | DNE  | |
| jammy | DNE  | |
| kinetic | DNE  | |
| lunar | DNE  | |
| mantic | DNE  | 
Показывать по
| Релиз | Статус | Примечание | 
|---|---|---|
| bionic | DNE  | |
| devel | DNE  | |
| esm-infra-legacy/trusty | deferred  | 2019-08-23 | 
| esm-infra/focal | DNE  | |
| focal | DNE  | |
| impish | DNE  | |
| jammy | DNE  | |
| kinetic | DNE  | |
| lunar | DNE  | |
| mantic | DNE  | 
Показывать по
| Релиз | Статус | Примечание | 
|---|---|---|
| bionic | DNE  | |
| devel | DNE  | |
| esm-infra-legacy/trusty | DNE  | |
| esm-infra/focal | DNE  | |
| esm-infra/xenial | released  | 9.5.25-0ubuntu0.16.04.1+esm2 | 
| focal | DNE  | |
| impish | DNE  | |
| jammy | DNE  | |
| kinetic | DNE  | |
| lunar | DNE  | 
Показывать по
Ссылки на источники
EPSS
8.8 High
CVSS3
Связанные уязвимости
A flaw was found in PostgreSQL. There is an issue with incomplete efforts to operate safely when a privileged user is maintaining another user's objects. The Autovacuum, REINDEX, CREATE INDEX, REFRESH MATERIALIZED VIEW, CLUSTER, and pg_amcheck commands activated relevant protections too late or not at all during the process. This flaw allows an attacker with permission to create non-temporary objects in at least one schema to execute arbitrary SQL functions under a superuser identity.
A flaw was found in PostgreSQL. There is an issue with incomplete efforts to operate safely when a privileged user is maintaining another user's objects. The Autovacuum, REINDEX, CREATE INDEX, REFRESH MATERIALIZED VIEW, CLUSTER, and pg_amcheck commands activated relevant protections too late or not at all during the process. This flaw allows an attacker with permission to create non-temporary objects in at least one schema to execute arbitrary SQL functions under a superuser identity.
A flaw was found in PostgreSQL. There is an issue with incomplete effo ...
EPSS
8.8 High
CVSS3