Lucene search

K
cnvdChina National Vulnerability DatabaseCNVD-2022-06539
HistoryNov 24, 2020 - 12:00 a.m.

PostgreSQL Arbitrary Code Execution Vulnerability (CNVD-2022-06539)

2020-11-2400:00:00
China National Vulnerability Database
www.cnvd.org.cn
13

0.004 Low

EPSS

Percentile

73.1%

PostgreSQL is a free object-relational database server (database management system) distributed under a flexible BSD-style license. an arbitrary code execution vulnerability exists in the psql interactive terminal in PostgreSQL. If an interactive psql session uses gset when querying the server, an attacker can exploit the vulnerability to execute arbitrary code with the privileges of the operating system account running psql.