Количество 60
Количество 60
GHSA-7h2q-899j-9636
Symlink following in PostgreSQL pg_basebackup plain format and in pg_rewind allows an origin superuser to overwrite local files, e.g. /var/lib/postgres/.bashrc, that hijack the operating system account. It will remain the case that starting the server after these commands implicitly trusts the origin superuser, due to features like shared_preload_libraries. Hence, the attack has practical implications only if one takes relevant action between these commands and server start, like moving the files to a different VM or snapshotting the VM. Versions before PostgreSQL 18.4, 17.10, 16.14, 15.18, and 14.23 are affected.
CVE-2026-6475
Symlink following in PostgreSQL pg_basebackup plain format and in pg_rewind allows an origin superuser to overwrite local files, e.g. /var/lib/postgres/.bashrc, that hijack the operating system account. It will remain the case that starting the server after these commands implicitly trusts the origin superuser, due to features like shared_preload_libraries. Hence, the attack has practical implications only if one takes relevant action between these commands and server start, like moving the files to a different VM or snapshotting the VM. Versions before PostgreSQL 18.4, 17.10, 16.14, 15.18, and 14.23 are affected.
CVE-2026-6475
Symlink following in PostgreSQL pg_basebackup plain format and in pg_rewind allows an origin superuser to overwrite local files, e.g. /var/lib/postgres/.bashrc, that hijack the operating system account. It will remain the case that starting the server after these commands implicitly trusts the origin superuser, due to features like shared_preload_libraries. Hence, the attack has practical implications only if one takes relevant action between these commands and server start, like moving the files to a different VM or snapshotting the VM. Versions before PostgreSQL 18.4, 17.10, 16.14, 15.18, and 14.23 are affected.
CVE-2026-6475
Symlink following in PostgreSQL pg_basebackup plain format and in pg_rewind allows an origin superuser to overwrite local files, e.g. /var/lib/postgres/.bashrc, that hijack the operating system account. It will remain the case that starting the server after these commands implicitly trusts the origin superuser, due to features like shared_preload_libraries. Hence, the attack has practical implications only if one takes relevant action between these commands and server start, like moving the files to a different VM or snapshotting the VM. Versions before PostgreSQL 18.4, 17.10, 16.14, 15.18, and 14.23 are affected.
CVE-2026-6475
PostgreSQL pg_basebackup and pg_rewind can overwrite unrelated files of origin superuser choice
CVE-2026-6475
Symlink following in PostgreSQL pg_basebackup plain format and in pg_r ...
BDU:2026-07100
Уязвимость утилит pg_basebackup и pg_rewind системы управления базами данных PostgreSQL, позволяющая нарушителю перезаписывать произвольные файлы
ROS-20260707-73-0058
Уязвимость postgresql16
ROS-20260706-80-0035
Уязвимость postgresql14
ROS-20260706-80-0034
Уязвимость postgresql18-1c
ROS-20260706-80-0033
Уязвимость postgresql18
ROS-20260706-80-0032
Уязвимость postgresql17-1c
ROS-20260706-80-0031
Уязвимость postgresql17
ROS-20260706-80-0030
Уязвимость postgresql16
ROS-20260706-80-0029
Уязвимость postgresql15-1c
ROS-20260706-80-0028
Уязвимость postgresql15
ROS-20260706-80-0027
Уязвимость postgresql-1c
ROS-20260706-80-0026
Уязвимость postgresql
ROS-20260706-73-0031
Уязвимость postgresql18-1c
ROS-20260706-73-0030
Уязвимость postgresql18
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
GHSA-7h2q-899j-9636 Symlink following in PostgreSQL pg_basebackup plain format and in pg_rewind allows an origin superuser to overwrite local files, e.g. /var/lib/postgres/.bashrc, that hijack the operating system account. It will remain the case that starting the server after these commands implicitly trusts the origin superuser, due to features like shared_preload_libraries. Hence, the attack has practical implications only if one takes relevant action between these commands and server start, like moving the files to a different VM or snapshotting the VM. Versions before PostgreSQL 18.4, 17.10, 16.14, 15.18, and 14.23 are affected. | CVSS3: 8.8 | 0% Низкий | 4 месяца назад | |
CVE-2026-6475 Symlink following in PostgreSQL pg_basebackup plain format and in pg_rewind allows an origin superuser to overwrite local files, e.g. /var/lib/postgres/.bashrc, that hijack the operating system account. It will remain the case that starting the server after these commands implicitly trusts the origin superuser, due to features like shared_preload_libraries. Hence, the attack has practical implications only if one takes relevant action between these commands and server start, like moving the files to a different VM or snapshotting the VM. Versions before PostgreSQL 18.4, 17.10, 16.14, 15.18, and 14.23 are affected. | CVSS3: 8.8 | 0% Низкий | 4 месяца назад | |
CVE-2026-6475 Symlink following in PostgreSQL pg_basebackup plain format and in pg_rewind allows an origin superuser to overwrite local files, e.g. /var/lib/postgres/.bashrc, that hijack the operating system account. It will remain the case that starting the server after these commands implicitly trusts the origin superuser, due to features like shared_preload_libraries. Hence, the attack has practical implications only if one takes relevant action between these commands and server start, like moving the files to a different VM or snapshotting the VM. Versions before PostgreSQL 18.4, 17.10, 16.14, 15.18, and 14.23 are affected. | CVSS3: 6.7 | 0% Низкий | 4 месяца назад | |
CVE-2026-6475 Symlink following in PostgreSQL pg_basebackup plain format and in pg_rewind allows an origin superuser to overwrite local files, e.g. /var/lib/postgres/.bashrc, that hijack the operating system account. It will remain the case that starting the server after these commands implicitly trusts the origin superuser, due to features like shared_preload_libraries. Hence, the attack has practical implications only if one takes relevant action between these commands and server start, like moving the files to a different VM or snapshotting the VM. Versions before PostgreSQL 18.4, 17.10, 16.14, 15.18, and 14.23 are affected. | CVSS3: 8.8 | 0% Низкий | 4 месяца назад | |
CVE-2026-6475 PostgreSQL pg_basebackup and pg_rewind can overwrite unrelated files of origin superuser choice | CVSS3: 8.8 | 0% Низкий | 4 месяца назад | |
CVE-2026-6475 Symlink following in PostgreSQL pg_basebackup plain format and in pg_r ... | CVSS3: 8.8 | 0% Низкий | 4 месяца назад | |
BDU:2026-07100 Уязвимость утилит pg_basebackup и pg_rewind системы управления базами данных PostgreSQL, позволяющая нарушителю перезаписывать произвольные файлы | CVSS3: 8.8 | 0% Низкий | 4 месяца назад | |
ROS-20260707-73-0058 Уязвимость postgresql16 | CVSS3: 8.8 | 0% Низкий | 2 месяца назад | |
ROS-20260706-80-0035 Уязвимость postgresql14 | CVSS3: 8.8 | 0% Низкий | 2 месяца назад | |
ROS-20260706-80-0034 Уязвимость postgresql18-1c | CVSS3: 8.8 | 0% Низкий | 2 месяца назад | |
ROS-20260706-80-0033 Уязвимость postgresql18 | CVSS3: 8.8 | 0% Низкий | 2 месяца назад | |
ROS-20260706-80-0032 Уязвимость postgresql17-1c | CVSS3: 8.8 | 0% Низкий | 2 месяца назад | |
ROS-20260706-80-0031 Уязвимость postgresql17 | CVSS3: 8.8 | 0% Низкий | 2 месяца назад | |
ROS-20260706-80-0030 Уязвимость postgresql16 | CVSS3: 8.8 | 0% Низкий | 2 месяца назад | |
ROS-20260706-80-0029 Уязвимость postgresql15-1c | CVSS3: 8.8 | 0% Низкий | 2 месяца назад | |
ROS-20260706-80-0028 Уязвимость postgresql15 | CVSS3: 8.8 | 0% Низкий | 2 месяца назад | |
ROS-20260706-80-0027 Уязвимость postgresql-1c | CVSS3: 8.8 | 0% Низкий | 2 месяца назад | |
ROS-20260706-80-0026 Уязвимость postgresql | CVSS3: 8.8 | 0% Низкий | 2 месяца назад | |
ROS-20260706-73-0031 Уязвимость postgresql18-1c | CVSS3: 8.8 | 0% Низкий | 2 месяца назад | |
ROS-20260706-73-0030 Уязвимость postgresql18 | CVSS3: 8.8 | 0% Низкий | 2 месяца назад |
Уязвимостей на страницу