Описание
Untrusted data inclusion in pg_dump in PostgreSQL allows a malicious superuser of the origin server to inject arbitrary code for restore-time execution as the client operating system account running psql to restore the dump, via psql meta-commands. pg_dumpall is also affected. pg_restore is affected when used to generate a plain-format dump. This is similar to MySQL CVE-2024-21096. Versions before PostgreSQL 17.6, 16.10, 15.14, 14.19, and 13.22 are affected.
| Релиз | Статус | Примечание | 
|---|---|---|
| devel | DNE  | |
| esm-infra/bionic | needs-triage  | |
| jammy | DNE  | |
| noble | DNE  | |
| plucky | DNE  | |
| questing | DNE  | |
| upstream | ignored  | end of life | 
Показывать по
| Релиз | Статус | Примечание | 
|---|---|---|
| devel | DNE  | |
| esm-infra/focal | needs-triage  | |
| jammy | DNE  | |
| noble | DNE  | |
| plucky | DNE  | |
| questing | DNE  | |
| upstream | ignored  | end of life | 
Показывать по
| Релиз | Статус | Примечание | 
|---|---|---|
| devel | DNE  | |
| jammy | released  | 14.19-0ubuntu0.22.04.1 | 
| noble | DNE  | |
| plucky | DNE  | |
| questing | DNE  | |
| upstream | released  | 14.19 | 
Показывать по
| Релиз | Статус | Примечание | 
|---|---|---|
| devel | DNE  | |
| jammy | DNE  | |
| noble | released  | 16.10-0ubuntu0.24.04.1 | 
| plucky | DNE  | |
| questing | DNE  | |
| upstream | released  | 16.10 | 
Показывать по
| Релиз | Статус | Примечание | 
|---|---|---|
| devel | released  | 17.6-1 | 
| jammy | DNE  | |
| noble | DNE  | |
| plucky | released  | 17.6-0ubuntu0.25.04.1 | 
| questing | released  | 17.6-1 | 
| upstream | released  | 17.6 | 
Показывать по
| Релиз | Статус | Примечание | 
|---|---|---|
| devel | DNE  | |
| esm-infra-legacy/trusty | deferred  | 2019-08-23 | 
| jammy | DNE  | |
| noble | DNE  | |
| plucky | DNE  | |
| questing | DNE  | |
| upstream | ignored  | end of life | 
Показывать по
| Релиз | Статус | Примечание | 
|---|---|---|
| devel | DNE  | |
| esm-infra/xenial | needs-triage  | |
| jammy | DNE  | |
| noble | DNE  | |
| plucky | DNE  | |
| questing | DNE  | |
| upstream | ignored  | end of life | 
Показывать по
EPSS
8.8 High
CVSS3
Связанные уязвимости
Untrusted data inclusion in pg_dump in PostgreSQL allows a malicious superuser of the origin server to inject arbitrary code for restore-time execution as the client operating system account running psql to restore the dump, via psql meta-commands. pg_dumpall is also affected. pg_restore is affected when used to generate a plain-format dump. This is similar to MySQL CVE-2024-21096. Versions before PostgreSQL 17.6, 16.10, 15.14, 14.19, and 13.22 are affected.
Untrusted data inclusion in pg_dump in PostgreSQL allows a malicious superuser of the origin server to inject arbitrary code for restore-time execution as the client operating system account running psql to restore the dump, via psql meta-commands. pg_dumpall is also affected. pg_restore is affected when used to generate a plain-format dump. This is similar to MySQL CVE-2024-21096. Versions before PostgreSQL 17.6, 16.10, 15.14, 14.19, and 13.22 are affected.
PostgreSQL pg_dump lets superuser of origin server execute arbitrary code in psql client
Untrusted data inclusion in pg_dump in PostgreSQL allows a malicious s ...
Untrusted data inclusion in pg_dump in PostgreSQL allows a malicious superuser of the origin server to inject arbitrary code for restore-time execution as the client operating system account running psql to restore the dump, via psql meta-commands. pg_dumpall is also affected. pg_restore is affected when used to generate a plain-format dump. This is similar to MySQL CVE-2024-21096. Versions before PostgreSQL 17.6, 16.10, 15.14, 14.19, and 13.22 are affected.
EPSS
8.8 High
CVSS3