Описание
IN THE EXTENSION SCRIPT, a SQL Injection vulnerability was found in PostgreSQL if it uses @extowner@, @extschema@, or @extschema:...@ inside a quoting construct (dollar quoting, '', or ""). If an administrator has installed files of a vulnerable, trusted, non-bundled extension, an attacker with database-level CREATE privilege can execute arbitrary code as the bootstrap superuser.
| Релиз | Статус | Примечание | 
|---|---|---|
| bionic | ignored  | end of standard support | 
| devel | DNE  | |
| esm-infra/bionic | needs-triage  | |
| esm-infra/focal | DNE  | |
| focal | DNE  | |
| jammy | DNE  | |
| lunar | DNE  | |
| mantic | DNE  | |
| noble | DNE  | |
| oracular | DNE  | 
Показывать по
| Релиз | Статус | Примечание | 
|---|---|---|
| bionic | DNE  | |
| devel | DNE  | |
| esm-infra/focal | released  | 12.16-0ubuntu0.20.04.1 | 
| focal | released  | 12.16-0ubuntu0.20.04.1 | 
| jammy | DNE  | |
| lunar | DNE  | |
| mantic | DNE  | |
| noble | DNE  | |
| oracular | DNE  | |
| plucky | DNE  | 
Показывать по
| Релиз | Статус | Примечание | 
|---|---|---|
| bionic | DNE  | |
| devel | DNE  | |
| esm-infra/focal | DNE  | |
| focal | DNE  | |
| jammy | released  | 14.9-0ubuntu0.22.04.1 | 
| lunar | DNE  | |
| mantic | DNE  | |
| noble | DNE  | |
| oracular | DNE  | |
| plucky | DNE  | 
Показывать по
| Релиз | Статус | Примечание | 
|---|---|---|
| bionic | ignored  | end of standard support | 
| devel | DNE  | |
| esm-infra/focal | DNE  | |
| focal | DNE  | |
| jammy | DNE  | |
| lunar | released  | 15.4-0ubuntu0.23.04.1 | 
| mantic | released  | 15.4-1ubuntu1 | 
| noble | DNE  | |
| oracular | DNE  | |
| plucky | DNE  | 
Показывать по
| Релиз | Статус | Примечание | 
|---|---|---|
| bionic | DNE  | |
| devel | DNE  | |
| esm-infra/focal | DNE  | |
| focal | DNE  | |
| jammy | DNE  | |
| lunar | DNE  | |
| mantic | DNE  | |
| noble | DNE  | |
| oracular | DNE  | |
| plucky | DNE  | 
Показывать по
| Релиз | Статус | Примечание | 
|---|---|---|
| bionic | DNE  | |
| devel | DNE  | |
| esm-infra-legacy/trusty | deferred  | 2019-08-23 | 
| esm-infra/focal | DNE  | |
| focal | DNE  | |
| jammy | DNE  | |
| lunar | DNE  | |
| mantic | DNE  | |
| noble | DNE  | |
| oracular | DNE  | 
Показывать по
| Релиз | Статус | Примечание | 
|---|---|---|
| bionic | DNE  | |
| devel | DNE  | |
| esm-infra/focal | DNE  | |
| esm-infra/xenial | released  | 9.5.25-0ubuntu0.16.04.1+esm5 | 
| focal | DNE  | |
| jammy | DNE  | |
| lunar | DNE  | |
| mantic | DNE  | |
| noble | DNE  | |
| oracular | DNE  | 
Показывать по
Ссылки на источники
EPSS
7.5 High
CVSS3
Связанные уязвимости
IN THE EXTENSION SCRIPT, a SQL Injection vulnerability was found in PostgreSQL if it uses @extowner@, @extschema@, or @extschema:...@ inside a quoting construct (dollar quoting, '', or ""). If an administrator has installed files of a vulnerable, trusted, non-bundled extension, an attacker with database-level CREATE privilege can execute arbitrary code as the bootstrap superuser.
IN THE EXTENSION SCRIPT, a SQL Injection vulnerability was found in PostgreSQL if it uses @extowner@, @extschema@, or @extschema:...@ inside a quoting construct (dollar quoting, '', or ""). If an administrator has installed files of a vulnerable, trusted, non-bundled extension, an attacker with database-level CREATE privilege can execute arbitrary code as the bootstrap superuser.
Postgresql: extension script @substitutions@ within quoting allow sql injection
IN THE EXTENSION SCRIPT, a SQL Injection vulnerability was found in Po ...
EPSS
7.5 High
CVSS3