Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 60

Количество 60

ubuntu логотип

CVE-2026-6475

4 месяца назад

Symlink following in PostgreSQL pg_basebackup plain format and in pg_rewind allows an origin superuser to overwrite local files, e.g. /var/lib/postgres/.bashrc, that hijack the operating system account. It will remain the case that starting the server after these commands implicitly trusts the origin superuser, due to features like shared_preload_libraries. Hence, the attack has practical implications only if one takes relevant action between these commands and server start, like moving the files to a different VM or snapshotting the VM. Versions before PostgreSQL 18.4, 17.10, 16.14, 15.18, and 14.23 are affected.

CVSS3: 8.8
EPSS: Низкий
redhat логотип

CVE-2026-6475

4 месяца назад

Symlink following in PostgreSQL pg_basebackup plain format and in pg_rewind allows an origin superuser to overwrite local files, e.g. /var/lib/postgres/.bashrc, that hijack the operating system account. It will remain the case that starting the server after these commands implicitly trusts the origin superuser, due to features like shared_preload_libraries. Hence, the attack has practical implications only if one takes relevant action between these commands and server start, like moving the files to a different VM or snapshotting the VM. Versions before PostgreSQL 18.4, 17.10, 16.14, 15.18, and 14.23 are affected.

CVSS3: 6.7
EPSS: Низкий
nvd логотип

CVE-2026-6475

4 месяца назад

Symlink following in PostgreSQL pg_basebackup plain format and in pg_rewind allows an origin superuser to overwrite local files, e.g. /var/lib/postgres/.bashrc, that hijack the operating system account. It will remain the case that starting the server after these commands implicitly trusts the origin superuser, due to features like shared_preload_libraries. Hence, the attack has practical implications only if one takes relevant action between these commands and server start, like moving the files to a different VM or snapshotting the VM. Versions before PostgreSQL 18.4, 17.10, 16.14, 15.18, and 14.23 are affected.

CVSS3: 8.8
EPSS: Низкий
msrc логотип

CVE-2026-6475

4 месяца назад

PostgreSQL pg_basebackup and pg_rewind can overwrite unrelated files of origin superuser choice

CVSS3: 8.8
EPSS: Низкий
debian логотип

CVE-2026-6475

4 месяца назад

Symlink following in PostgreSQL pg_basebackup plain format and in pg_r ...

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-7h2q-899j-9636

4 месяца назад

Symlink following in PostgreSQL pg_basebackup plain format and in pg_rewind allows an origin superuser to overwrite local files, e.g. /var/lib/postgres/.bashrc, that hijack the operating system account. It will remain the case that starting the server after these commands implicitly trusts the origin superuser, due to features like shared_preload_libraries. Hence, the attack has practical implications only if one takes relevant action between these commands and server start, like moving the files to a different VM or snapshotting the VM. Versions before PostgreSQL 18.4, 17.10, 16.14, 15.18, and 14.23 are affected.

CVSS3: 8.8
EPSS: Низкий
rocky логотип

RLSA-2026:28037

3 месяца назад

Important: postgresql:15 security update

EPSS: Низкий
rocky логотип

RLSA-2026:27743

3 месяца назад

Important: postgresql16 security update

EPSS: Низкий
rocky логотип

RLSA-2026:27742

3 месяца назад

Important: postgresql18 security update

EPSS: Низкий
rocky логотип

RLSA-2026:27738

3 месяца назад

Important: libpq security update

EPSS: Низкий
rocky логотип

RLSA-2026:26204

3 месяца назад

Important: postgresql:18 security update

EPSS: Низкий
rocky логотип

RLSA-2026:26203

3 месяца назад

Important: postgresql:16 security update

EPSS: Низкий
rocky логотип

RLSA-2026:26181

3 месяца назад

Important: postgresql:15 security update

EPSS: Низкий
oracle-oval логотип

ELSA-2026-28037

3 месяца назад

ELSA-2026-28037: postgresql:15 security update (IMPORTANT)

EPSS: Низкий
oracle-oval логотип

ELSA-2026-27743

около 2 месяцев назад

ELSA-2026-27743: postgresql16 security update (IMPORTANT)

EPSS: Низкий
oracle-oval логотип

ELSA-2026-27741

3 месяца назад

ELSA-2026-27741: postgresql security update (IMPORTANT)

EPSS: Низкий
oracle-oval логотип

ELSA-2026-27738

3 месяца назад

ELSA-2026-27738: libpq security update (IMPORTANT)

EPSS: Низкий
oracle-oval логотип

ELSA-2026-26204

2 месяца назад

ELSA-2026-26204: postgresql:18 security update (IMPORTANT)

EPSS: Низкий
oracle-oval логотип

ELSA-2026-26203

3 месяца назад

ELSA-2026-26203: postgresql:16 security update (IMPORTANT)

EPSS: Низкий
rocky логотип

RLSA-2026:27741

около 2 месяцев назад

Important: postgresql security update

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2026-6475

Symlink following in PostgreSQL pg_basebackup plain format and in pg_rewind allows an origin superuser to overwrite local files, e.g. /var/lib/postgres/.bashrc, that hijack the operating system account. It will remain the case that starting the server after these commands implicitly trusts the origin superuser, due to features like shared_preload_libraries. Hence, the attack has practical implications only if one takes relevant action between these commands and server start, like moving the files to a different VM or snapshotting the VM. Versions before PostgreSQL 18.4, 17.10, 16.14, 15.18, and 14.23 are affected.

CVSS3: 8.8
0%
Низкий
4 месяца назад
redhat логотип
CVE-2026-6475

Symlink following in PostgreSQL pg_basebackup plain format and in pg_rewind allows an origin superuser to overwrite local files, e.g. /var/lib/postgres/.bashrc, that hijack the operating system account. It will remain the case that starting the server after these commands implicitly trusts the origin superuser, due to features like shared_preload_libraries. Hence, the attack has practical implications only if one takes relevant action between these commands and server start, like moving the files to a different VM or snapshotting the VM. Versions before PostgreSQL 18.4, 17.10, 16.14, 15.18, and 14.23 are affected.

CVSS3: 6.7
0%
Низкий
4 месяца назад
nvd логотип
CVE-2026-6475

Symlink following in PostgreSQL pg_basebackup plain format and in pg_rewind allows an origin superuser to overwrite local files, e.g. /var/lib/postgres/.bashrc, that hijack the operating system account. It will remain the case that starting the server after these commands implicitly trusts the origin superuser, due to features like shared_preload_libraries. Hence, the attack has practical implications only if one takes relevant action between these commands and server start, like moving the files to a different VM or snapshotting the VM. Versions before PostgreSQL 18.4, 17.10, 16.14, 15.18, and 14.23 are affected.

CVSS3: 8.8
0%
Низкий
4 месяца назад
msrc логотип
CVE-2026-6475

PostgreSQL pg_basebackup and pg_rewind can overwrite unrelated files of origin superuser choice

CVSS3: 8.8
0%
Низкий
4 месяца назад
debian логотип
CVE-2026-6475

Symlink following in PostgreSQL pg_basebackup plain format and in pg_r ...

CVSS3: 8.8
0%
Низкий
4 месяца назад
github логотип
GHSA-7h2q-899j-9636

Symlink following in PostgreSQL pg_basebackup plain format and in pg_rewind allows an origin superuser to overwrite local files, e.g. /var/lib/postgres/.bashrc, that hijack the operating system account. It will remain the case that starting the server after these commands implicitly trusts the origin superuser, due to features like shared_preload_libraries. Hence, the attack has practical implications only if one takes relevant action between these commands and server start, like moving the files to a different VM or snapshotting the VM. Versions before PostgreSQL 18.4, 17.10, 16.14, 15.18, and 14.23 are affected.

CVSS3: 8.8
0%
Низкий
4 месяца назад
rocky логотип
RLSA-2026:28037

Important: postgresql:15 security update

3 месяца назад
rocky логотип
RLSA-2026:27743

Important: postgresql16 security update

3 месяца назад
rocky логотип
RLSA-2026:27742

Important: postgresql18 security update

3 месяца назад
rocky логотип
RLSA-2026:27738

Important: libpq security update

3 месяца назад
rocky логотип
RLSA-2026:26204

Important: postgresql:18 security update

3 месяца назад
rocky логотип
RLSA-2026:26203

Important: postgresql:16 security update

3 месяца назад
rocky логотип
RLSA-2026:26181

Important: postgresql:15 security update

3 месяца назад
oracle-oval логотип
ELSA-2026-28037

ELSA-2026-28037: postgresql:15 security update (IMPORTANT)

3 месяца назад
oracle-oval логотип
ELSA-2026-27743

ELSA-2026-27743: postgresql16 security update (IMPORTANT)

около 2 месяцев назад
oracle-oval логотип
ELSA-2026-27741

ELSA-2026-27741: postgresql security update (IMPORTANT)

3 месяца назад
oracle-oval логотип
ELSA-2026-27738

ELSA-2026-27738: libpq security update (IMPORTANT)

3 месяца назад
oracle-oval логотип
ELSA-2026-26204

ELSA-2026-26204: postgresql:18 security update (IMPORTANT)

2 месяца назад
oracle-oval логотип
ELSA-2026-26203

ELSA-2026-26203: postgresql:16 security update (IMPORTANT)

3 месяца назад
rocky логотип
RLSA-2026:27741

Important: postgresql security update

около 2 месяцев назад

Уязвимостей на страницу