Lucene search

K
kasperskyKaspersky LabKLA71453
HistoryAug 08, 2024 - 12:00 a.m.

KLA71453 ACE vulnerability in PostgreSQL

2024-08-0800:00:00
Kaspersky Lab
threats.kaspersky.com
12
postgresql
toctou
vulnerability
malicious users
arbitrary code execution
update

CVSS3

8.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

AI Score

8

Confidence

Low

EPSS

0.001

Percentile

20.0%

Time-of-check Time-of-use (TOCTOU) race condition vulnerability was found in PostgreSQL. Malicious users can exploit this vulnerability to execute arbitrary code.

Original advisories

PostgreSQL: CVE-2024-7348: PostgreSQL relation replacement during pg_dump executes arbitrary SQL

Related products

PostgreSQL

CVE list

CVE-2024-7348 unknown

Solution

Update to the latest version

Download PostgreSQL

Impacts

  • ACE

Arbitrary code execution. Exploitation of vulnerabilities with this impact can lead to executing by abuser any code or commands at vulnerable machine or process.

Affected Products

  • PostgreSQL 16.x earlier than 16.8PostgreSQL 15.x earlier than 15.8PostgreSQL 14.x earlier than 14.13PostgreSQL 13.x earlier than 13.16PostgreSQL 12.x earlier than 12.20

CVSS3

8.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

AI Score

8

Confidence

Low

EPSS

0.001

Percentile

20.0%